AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
High 74 Cryptographic libraries

fix: return early in sensitive methods for --restricted-rpc

Public commit record

What the developer wrote

Authored by SNeedlewoods

62/100 · Adequate
fix: return early in sensitive methods for --restricted-rpc
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope! No meaningful explanatory body
The short version

What changed, and why it matters

This patch fixes a security gap in Monero's wallet RPC server when it runs in '--restricted-rpc' mode. That mode is meant to block sensitive wallet commands from remote callers, but several methods were checking whether a wallet was open before checking the restricted flag. A remote attacker could therefore call those methods on a restricted RPC server and trigger errors or behavior that should have been blocked outright. The fix moves the restricted-mode check to the very beginning of each sensitive command so it is denied immediately.

Recommended action

Treat this as a security fix and include it in release notes. Users running wallet RPC servers with --restricted-rpc should upgrade. Review any custom RPC handlers not touched by this commit to ensure they also deny restricted callers before performing state checks or operations.

Security signals we found

01

Authorization bypass hardening: restricted-mode check moved before wallet-open check, preventing restricted callers from reaching wallet logic even when no wallet is loaded

02

Multiple RPC handlers lacked an early restricted-mode denial

03

Macro refactor centralizes restricted/background-sync validation

04

Sensitive operations (create address/account, transfers, signing, key export, wallet open/close/create, password change, mining control, daemon change) now uniformly deny restricted callers first

Risk score

Why this scored 74/100

Our methodology →
Potential impact 22/30
Exploitability 18/25
Stealth signal 10/15
Affected reach 12/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.