What changed, and why it matters
This commit updates a dependency called flutter_mwebd from version 0.0.1-pre.10 to 0.0.1-pre.11 and adds one debug log line when preparing a Mimblewimble (MWEB) cryptocurrency transaction. There is no description of why the dependency was updated or what changed in the new version. The added log line prints transaction preparation data, which could include sensitive details, but the commit itself does not show a fix for a clear security vulnerability.
Review the flutter_mwebd 0.0.1-pre.11 changelog or source diff to determine whether this update fixes a security issue. Also verify that the newly added debug log does not write sensitive MWEB transaction data to persistent or shared logs.
Security signals we found
Dependency version bump for a privacy-sensitive MWEB component without disclosed changelog or security rationale
New debug log statement in transaction preparation path may leak sensitive MWEB transaction data to logs
Evidence from the diff
The diff updates the flutter_mwebd package (a Dart wrapper for the mwebd daemon used for Litecoin MWEB transactions) to a newer pre-release version and pins it exactly in the template. It also adds a debug log statement in electrumx_interface.dart inside the MWEB send preparation path. The actual security-relevant changes, if any, are inside the updated flutter_mwebd package, which is not shown in this diff. No CVE, advisory, or vendor security explanation is present.
Changed components
flutter_mwebd dependencylib/wallets/wallet/wallet_mixin_interfaces/electrumx_interface.dartMWEB transaction preparation flowInspect captured patch +4 / −3
diff --git a/lib/wallets/wallet/wallet_mixin_interfaces/electrumx_interface.dart b/lib/wallets/wallet/wallet_mixin_interfaces/electrumx_interface.dart
index c5dcd27..98fd505 100644
--- a/lib/wallets/wallet/wallet_mixin_interfaces/electrumx_interface.dart
+++ b/lib/wallets/wallet/wallet_mixin_interfaces/electrumx_interface.dart
@@ -1942,6 +1942,7 @@ mixin ElectrumXInterface<T extends ElectrumXCurrencyInterface>
final data = await (this as MwebInterface).processMwebTransaction(
mwebData,
);
+ Logging.instance.d("prepare MWEB send: $data");
return data.copyWith(fee: fee);
}
diff --git a/pubspec.lock b/pubspec.lock
index b985461..6455075 100644
--- a/pubspec.lock
+++ b/pubspec.lock
@@ -1061,10 +1061,10 @@ packages:
dependency: "direct main"
description:
name: flutter_mwebd
- sha256: faaec843d9749c5d3cd02e9c7afbd7754449f93a4316fec43b2c26f372e0eb55
+ sha256: "14f2a331b2621b78ddf62081ca8a466f6a2b4352a66950fffd68615c14e63edf"
url: "https://pub.dev"
source: hosted
- version: "0.0.1-pre.10"
+ version: "0.0.1-pre.11"
flutter_native_splash:
dependency: "direct main"
description:
diff --git a/scripts/app_config/templates/pubspec.template.yaml b/scripts/app_config/templates/pubspec.template.yaml
index 0723e2d..030c902 100644
--- a/scripts/app_config/templates/pubspec.template.yaml
+++ b/scripts/app_config/templates/pubspec.template.yaml
@@ -76,7 +76,7 @@ dependencies:
# %%END_ENABLE_SAL%%
# %%ENABLE_MWEBD%%
-# flutter_mwebd: ^0.0.1-pre.10
+# flutter_mwebd: 0.0.1-pre.11
# %%END_ENABLE_MWEBD%%
monero_rpc: ^2.0.0
Why this scored 11/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.