simplewallet: don't ignore misplaced index= in sweep commands
What changed, and why it matters
This change fixes a bug in Monero's command-line wallet (simplewallet) where a user typing 'index=' in the wrong position of a 'sweep' command could be silently ignored. Previously, the wallet only checked the very first word for 'index='; if it appeared later, the wallet would act as if no subaddress index was specified, potentially sweeping funds from unintended addresses. The fix scans all words for 'index=' and removes it when found. This is primarily a usability/transaction-safety bug rather than a remote-exploitable vulnerability.
Users of the Monero CLI wallet should upgrade to a version containing this commit to avoid accidental mis-sweeps. Reviewers should consider whether additional 'index=' occurrences should also be rejected rather than silently ignored, and whether other commands have similar positional-argument parsing issues.
Security signals we found
Argument parsing bug causing user intent to be silently ignored
Potential unintended fund sweep due to ignored subaddress index
No input validation bypass or memory corruption
Fix is localized and partial (only handles first 'index=' occurrence, breaks after match)
Evidence from the diff
In simple_wallet::sweep_main(), subaddress index parsing was previously only performed if local_args[0] began with ‘index=’. If the user placed index= anywhere else in the argument list, it was silently ignored and the sweep proceeded with an empty subaddr_indices set, defaulting to index 0. The patch replaces the single-position check with a loop that scans all arguments for the ‘index=’ prefix, parses/removes it, and breaks after the first match. This prevents accidental misuse where a user believes they are sweeping from a specific subaddress but are not.
Changed components
src/simplewallet/simplewallet.cppsimple_wallet::sweep_main()CLI sweep commands (sweep_all, sweep_below, sweep_single, sweep_unmixable)Inspect captured patch +7 / −4
diff --git a/src/simplewallet/simplewallet.cpp b/src/simplewallet/simplewallet.cpp
index cbd6554..a46f658 100644
--- a/src/simplewallet/simplewallet.cpp
+++ b/src/simplewallet/simplewallet.cpp
@@ -6871,19 +6871,22 @@ bool simple_wallet::sweep_main(uint32_t account, uint64_t below, const std::vect
std::vector<std::string> local_args = args_;
std::set<uint32_t> subaddr_indices;
- if (local_args.size() > 0 && local_args[0].substr(0, 6) == "index=")
+ for (auto it = local_args.begin(); it != local_args.end(); ++it)
{
- if (local_args[0] == "index=all")
+ if (it->substr(0, 6) != "index=")
+ continue;
+ if (*it == "index=all")
{
for (uint32_t i = 0; i < m_wallet->get_num_subaddresses(account); ++i)
subaddr_indices.insert(i);
}
- else if (!parse_subaddress_indices(local_args[0], subaddr_indices))
+ else if (!parse_subaddress_indices(*it, subaddr_indices))
{
print_usage();
return true;
}
- local_args.erase(local_args.begin());
+ local_args.erase(it);
+ break;
}
fee_priority priority = fee_priority::Default;
Why this scored 35/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.