AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 51 Cryptographic libraries

wallet_rpc_server: restrict relay_tx

Public commit record

What the developer wrote

Authored by selsta

35/100 · Opaque
wallet_rpc_server: restrict relay_tx
✓ Descriptive subject! No meaningful explanatory body
The short version

What changed, and why it matters

This commit adds a security check to the Monero wallet's remote-control interface (RPC server). It now refuses the 'relay_tx' command when the server is running in 'restricted' mode. Before this change, a user or attacker with RPC access could potentially ask a restricted wallet to broadcast a transaction it had prepared, which restricted mode was apparently meant to prevent. The fix is small and defensive, but the commit message does not explain whether this was an actual bug or just a hardening measure.

Recommended action

Treat as a low-to-moderate hardening fix. Review whether other RPC commands in restricted mode have similar gaps. Apply the patch and audit related handlers (submit_transfer, sweep_all, etc.) for consistent restricted-mode enforcement. No urgent incident response is indicated by the diff alone.

Security signals we found

01

Authorization bypass hardening: restricted RPC mode was not enforcing on relay_tx

02

RPC command now returns explicit denial in restricted mode

03

Transaction relay is a state-changing network operation

04

Patch is partial/hardening; no CVE or incident details provided

Risk score

Why this scored 51/100

Our methodology →
Potential impact 12/30
Exploitability 10/25
Stealth signal 8/15
Affected reach 10/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.