What changed, and why it matters
This commit adds a security check to the Monero wallet's remote-control interface (RPC server). It now refuses the 'relay_tx' command when the server is running in 'restricted' mode. Before this change, a user or attacker with RPC access could potentially ask a restricted wallet to broadcast a transaction it had prepared, which restricted mode was apparently meant to prevent. The fix is small and defensive, but the commit message does not explain whether this was an actual bug or just a hardening measure.
Treat as a low-to-moderate hardening fix. Review whether other RPC commands in restricted mode have similar gaps. Apply the patch and audit related handlers (submit_transfer, sweep_all, etc.) for consistent restricted-mode enforcement. No urgent incident response is indicated by the diff alone.
Security signals we found
Authorization bypass hardening: restricted RPC mode was not enforcing on relay_tx
RPC command now returns explicit denial in restricted mode
Transaction relay is a state-changing network operation
Patch is partial/hardening; no CVE or incident details provided
Evidence from the diff
The patch modifies wallet_rpc_server::on_relay_tx in src/wallet/wallet_rpc_server.cpp to return WALLET_RPC_ERROR_CODE_DENIED with message ‘Command unavailable in restricted mode.’ when m_restricted is true. The command relays a previously created transaction to the Monero network. Restricted RPC mode is intended to limit sensitive operations, and this change aligns relay_tx with that intent. The diff is a 7-line guard added at the top of the handler; no other logic changes.
Changed components
src/wallet/wallet_rpc_server.cppwallet RPC serverCOMMAND_RPC_RELAY_TX handlerInspect captured patch +7 / −0
diff --git a/src/wallet/wallet_rpc_server.cpp b/src/wallet/wallet_rpc_server.cpp
index 6691d55..72fa414 100644
--- a/src/wallet/wallet_rpc_server.cpp
+++ b/src/wallet/wallet_rpc_server.cpp
@@ -1925,6 +1925,13 @@ namespace tools
//------------------------------------------------------------------------------------------------------------------------------
bool wallet_rpc_server::on_relay_tx(const wallet_rpc::COMMAND_RPC_RELAY_TX::request& req, wallet_rpc::COMMAND_RPC_RELAY_TX::response& res, epee::json_rpc::error& er, const connection_context *ctx)
{
+ if (m_restricted)
+ {
+ er.code = WALLET_RPC_ERROR_CODE_DENIED;
+ er.message = "Command unavailable in restricted mode.";
+ return false;
+ }
+
if (!m_wallet) return not_open(er);
cryptonote::blobdata blob;
Why this scored 51/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.