What changed, and why it matters
This is a small code change in a wallet address storage routine. The developer switched from iterating over a map's keys and looking up values one by one, to copying both keys and values into separate fixed lists before inserting them. A comment says they need to investigate why the address list was changing partway through the loop. This suggests the old code could have used stale or mismatched data, but the patch is a workaround rather than a complete fix. There is no clear security vulnerability shown in the diff itself.
Treat this as a routine defensive fix. Review the caller(s) of setAddresses to confirm the map cannot be modified concurrently, and investigate the TODO about why the list changes mid-loop. Add input validation and remove the non-null assertion if possible. No urgent security patch is indicated by this commit alone.
Security signals we found
Code change touches wallet address persistence layer
Inline TODO suggests unresolved race condition or mutation bug
Use of non-null assertion operator (!) remains, so null safety relies on caller
No input validation or sanitization visible in the changed function
Evidence from the diff
In cw_core/lib/wallet_info.dart, setAddresses(Map
Changed components
cw_core/lib/wallet_info.dartWalletInfo.setAddressesWalletInfoAddressMapInspect captured patch +4 / −2
diff --git a/cw_core/lib/wallet_info.dart b/cw_core/lib/wallet_info.dart
index 3f2d9c05..1ce39726 100644
--- a/cw_core/lib/wallet_info.dart
+++ b/cw_core/lib/wallet_info.dart
@@ -429,8 +429,10 @@ class WalletInfo {
Future<void> setAddresses(Map<String, String> addresses) async {
await WalletInfoAddressMap.deleteByWalletInfoId(internalId);
final keys = addresses.keys.toList();
- for (final address in keys) {
- await WalletInfoAddressMap.insert(internalId, address, addresses[address]!);
+ final values = addresses.values.toList();
+ // ToDo: check why the addresses list gets changed half way through
+ for (int i = 0; i < keys.length; i++) {
+ await WalletInfoAddressMap.insert(internalId, keys[i], values[i]);
}
}
Why this scored 17/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.