Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Disclose ERC-1271 vulnerability when app data can be manipulated (#437)
# Description Adds a new vulnerability disclosure for ERC-1271 orders. This used to affect Milkman orders but has been fixed in cowdao-grants/milkman#1 and related infrastructure in cowprotocol/milkman-bot#5. No "official" contracts are affected by this issue anymore. ## Credits This issue was brought to our attention thanks to the report by Quantura Tech with their analysis of the negative effects on the solver competition when order fees can be manipulated. ## Reference Internal discussion about the disclosure [here](https://cowservices.slack.com/archives/C03JTHY9CUU/p1727861224310599).
- Loading branch information