highVulnerability

GHSA-429q-fhh4-r6hj

### Impact Any uses of `InterfaceAccount` allows another unexpected account type to be passed, after https://github.com/solana-foundation/anchor/pull/3837 disabled discriminator checking for this type. The bug was originally reported and fixed in https://github.com/solana-foundation/anchor/pull/4139, see that PR for more details. ### Patches https://github.com/solana-foundation/anchor/pull/4139 patched the issue and was released in `1.0.0-rc.2`. Users should upgrade to the latest released version of Anchor 1.0. ### References Bug landed in: https://github.com/solana-foundation/anchor/pull/3837 Bug fixed in: https://github.com/solana-foundation/anchor/pull/4139

Properties

ghsa_id
GHSA-429q-fhh4-r6hj
severity
high
summary
Anchor: `InterfaceAccount` allows account substitution between unexpected types
cve_id
GHSA-429q-fhh4-r6hj
is_ghsa_only
true
ghsa_published
2026-05-13T15:33:46Z
source_url
https://github.com/advisories/GHSA-429q-fhh4-r6hj
ghsa_updated
2026-05-19T20:18:36Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]rust/anchor-lang

AFFECTS (1)

[Software]rust/anchor-lang

HAS_WEAKNESS (1)

[Weakness]Improper Input Validation

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-429q-fhh4-r6hj — Ninja Signal Threat Intelligence | Ninja Signal