Skip to content
Latest alertgo-ethereum v1.17.8 security release fixes p2p DoS issues and a STUN-response node crash
0xCERT
All advisories
High0xCERT-2026-0197·

Anchor: Program<'info, System> is not properly validated

Anchor: Program<'info, System> is not properly validated. An logic error causes anchor programs to accept any program id when requiring the system program id, causing false assumptions resulting in potential arbitrary cpi in programs that invoke system program instructions.

Vuln-watch · relayed from the GitHub Advisory Database; see Source & attribution below

Affected chainsSolana

Summary

An logic error causes anchor programs to accept any program id when requiring the system program id, causing false assumptions resulting in potential arbitrary cpi in programs that invoke system program instructions.

Affected

  • anchor-lang (rust) >= 1.0.0, < 1.0.2 — fixed in 1.0.2

Severity

High, as rated by the upstream advisory.

Recommended actions

  • Upgrade anchor-lang to 1.0.2 or later

Source & attribution

This 0xCERT advisory summarises GHSA-c6rc-8jpp-2fgc / CVE-2026-45137 from the GitHub Advisory Database, credited upstream to Matthias1590: https://github.com/advisories/GHSA-c6rc-8jpp-2fgc. Details may change; refer to the original source for the authoritative record.

OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.

Published 2026-05-13 · last updated 2026-10-08

curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0197/signed.txt | gpg --verify