What changed, and why it matters
This small update tightens how the app handles fee-estimate responses from an EVM (Ethereum-compatible) network API. Before, if the server returned a successful HTTP status but the 'result' field was not a list, the app could crash while trying to process it. Now the app checks that 'result' is actually a list before using it. The second file change is just a routine dependency lock-file cleanup and appears unrelated to security.
Treat as a low-severity hardening fix. Review whether other JSON casts in the same client and similar clients lack type-shape validation, and consider adding consistent response-schema validation for RPC endpoints.
Security signals we found
Type-cast hardening on untrusted JSON input
Possible denial-of-service/crash vector from unexpected RPC response shape
No explicit security framing by vendor in commit title/message
Evidence from the diff
In cw_evm/lib/clients/evm_chain_client.dart, the condition guarding fee-history parsing is extended with && jsonResponse['result'] is List. Previously the guard only checked HTTP 2xx and jsonResponse['status'] != 0; if a compliant-but-unexpected JSON body had result as a non-list (e.g., string error message, null, or map), the subsequent (jsonResponse['result'] as List).map(...) cast would throw a runtime exception. This is a hardening/robustness fix against malformed or unexpected RPC responses. The pubspec.lock removal of frontend_server_client is a transitive dependency change with no apparent security relevance in the diff.
Changed components
cw_evm/lib/clients/evm_chain_client.dartEVM chain fee estimation / gas price fetchingInspect captured patch +2 / −9
diff --git a/cw_evm/lib/clients/evm_chain_client.dart b/cw_evm/lib/clients/evm_chain_client.dart
index 0d51e8f1..48e1f5fa 100644
--- a/cw_evm/lib/clients/evm_chain_client.dart
+++ b/cw_evm/lib/clients/evm_chain_client.dart
@@ -144,7 +144,8 @@ class EVMChainClient {
final jsonResponse = json.decode(response.body) as Map<String, dynamic>;
- if (response.statusCode >= 200 && response.statusCode < 300 && jsonResponse['status'] != 0) {
+ if (response.statusCode >= 200 && response.statusCode < 300 && jsonResponse['status'] != 0 &&
+ jsonResponse['result'] is List) {
final symbol = EVMChainUtils.getFeeCurrency(chainId);
return (jsonResponse['result'] as List)
diff --git a/cw_monero/pubspec.lock b/cw_monero/pubspec.lock
index 58652bc8..79da3694 100644
--- a/cw_monero/pubspec.lock
+++ b/cw_monero/pubspec.lock
@@ -333,14 +333,6 @@ packages:
url: "https://pub.dev"
source: hosted
version: "1.1.0"
- frontend_server_client:
- dependency: transitive
- description:
- name: frontend_server_client
- sha256: f64a0333a82f30b0cca061bc3d143813a486dc086b574bfb233b7c1372427694
- url: "https://pub.dev"
- source: hosted
- version: "4.0.0"
glob:
dependency: transitive
description:
Why this scored 25/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.