Context-Inappropriate Capability
Medium
- Confidence
- 93% confidence
- Finding
- The bridge page will execute whatever action object the Node side serves, including arbitrary `personal_sign` messages and arbitrary `eth_sendTransaction` calls with attacker-controlled `to`, `data`, and `value`. In a wallet-enabled browser context, this creates a generic wallet-command channel that exceeds the narrow registration/SBT-mint scope and could be abused to solicit signatures or transactions unrelated to the intended flow.
