AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 48 Cryptographic libraries

wallet: initialize URI parse outputs

Public commit record

What the developer wrote

Authored by Samy

68/100 · Adequate
wallet: initialize URI parse outputs

Successful parses left optional outputs unchanged when the URI omitted them, which could expose stale values or an uninitialized amount

Initialize them after validating the address so outputs only describe the current URI
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
The short version

What changed, and why it matters

This change fixes a bug in how Monero wallet software reads payment web links (URIs). Before the fix, if a payment link did not specify an amount, description, or other optional fields, the wallet could accidentally keep leftover values from a previous parse. That could mislead the user into sending the wrong amount or seeing wrong payment details. The patch now clears those fields right after confirming the address is valid, and adds a test to prove it.

Recommended action

Treat as a low-to-moderate reliability/security fix. Merge the patch and backport to maintained branches. Wallet integrators should ensure they do not rely on parse_uri output parameters retaining values across calls, and should update to a release containing this fix.

Security signals we found

01

Use of uninitialized or stale output values after a successful parse

02

Potential UI/display of wrong payment amount or metadata

03

Information disclosure of prior parse state to subsequent callers

04

Fix includes regression test

Risk score

Why this scored 48/100

Our methodology →
Potential impact 12/30
Exploitability 8/25
Stealth signal 10/15
Affected reach 7/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.