AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 26 Cryptographic libraries

wallet: fix RPC describe transfer source entry

Public commit record

What the developer wrote

Authored by jeffro256

45/100 · Thin
wallet: fix RPC describe transfer source entry
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
The short version

What changed, and why it matters

This commit fixes a bug in the Monero wallet's RPC 'describe transfer' feature. Previously, the code used the wrong index (real_output_in_tx_index) to look up the real ring member in the list of possible transaction sources. The fix uses the correct index (real_output). This could have caused the RPC response to report the wrong global index and public key for the real source of funds, potentially misleading wallet users or downstream tools that rely on this data.

Recommended action

Review whether the incorrect index could leak or misreport sensitive ring-member information, and confirm the fix is backported to maintained branches. Audit other uses of real_output_in_tx_index versus real_output in the wallet RPC code.

Security signals we found

01

Incorrect index used to identify real transaction source in RPC output

02

Potential information disclosure or misattribution of transfer source

03

Fix aligns source lookup with intended field semantics

Risk score

Why this scored 26/100

Our methodology →
Potential impact 5/30
Exploitability 3/25
Stealth signal 4/15
Affected reach 5/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.