CVE-2024-24567 is a medium-severity vulnerability affecting Vyper compiler versions 0.3.10 and earlier, a Pythonic smart contract language for Ethereum. The flaw allows developers to mistakenly believe a value will be sent during delegatecall or staticcall operations, as the compiler silently ignores the 'value=' argument, which is semantically impossible for these EVM opcodes. With a CVSS score of 5.3, this vulnerability has a low impact on integrity and requires no user interaction or privileges, but could lead to unexpected contract behavior if developers are unaware of EVM semantics. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.3.10CPE matchmatch criteria | cpe:2.3:a:vyperlang:vyper:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.