ID
Severity
Status
Title 32 Findings
Location
M-01
MAJOR
FIXED

Deposit may result in near-zero shares minted

W-01
WARNING
FIXED

Division by Zero Risk in AdministrationSetters

AdministrationSetters.sol
W-02
WARNING
FIXED

Missing Zero Address Validation in Constructors in AaveV3Connector, MorphoConnector

AaveV3Connector.sol
MorphoConnector.sol
W-03
WARNING
FIXED

Missing Validation for eMode Category Existence in AaveV3Connector

AaveV3Connector.sol
W-04
WARNING
FIXED

Missing Verification of Support for Borrow and Collateral Tokens in AaveV3OracleConnector, MorphoOracleConnector

AaveV3OracleConnector.sol
MorphoOracleConnector.sol
W-05
WARNING
FIXED

Missing Data Validation in MorphoConnector

MorphoConnector.sol
W-06
WARNING
ACKNOWLEDGED

Non-Upgradeable Contract in MorphoConnector, AaveV3Connector, VaultBalanceAsLendingConnector,AaveV3OracleConnector, MorphoOracleConnector, ConstantSlippageConnector

AaveV3Connector.sol
MorphoConnector.sol
VaultBalanceAsLendingConnector.sol
AaveV3OracleConnector.sol
MorphoOracleConnector.sol
ConstantSlippageConnector.sol
W-07
WARNING
FIXED

Weak Address Validation in ModulesProvider

ModulesProvider.sol
W-08
WARNING
ACKNOWLEDGED

No Signature Expiry in WhitelistRegistry

WhitelistRegistry.sol
W-09
WARNING
FIXED

Storage Incompatibility Risk in AdministrationWrite

AdministrationWrite.sol
W-10
WARNING
FIXED

Unsafe Delegatecall in InitializeWrite

InitializeWrite.sol
W-11
WARNING
FIXED

Unclear Deleveraging State in OnlyEmergencyDeleverager

OnlyEmergencyDeleverager.sol
W-12
WARNING
ACKNOWLEDGED

Unrestricted approve Function in Approve

Approve.sol
W-13
WARNING
FIXED

Missing Zero Address Check in Approve

Approve.sol
W-14
WARNING
FIXED

Missing Balance Checks in Transfer, TransferFrom, and Burn

Transfer.sol
TransferFrom.sol
ERC20.sol
W-15
WARNING
FIXED

Zero Address Receiver in Mint, MintCollateral, Redeem, RedeemCollateral, Withdraw, and WithdrawCollateral

Mint.sol
Redeem.sol
Withdraw.sol
MintCollateral.sol
RedeemCollateral.sol
WithdrawCollateral.sol
W-16
WARNING
FIXED

Unsafe Delegatecall to Zero Address in AdministrationSetters

AdministrationSetters.sol
W-17
WARNING
ACKNOWLEDGED

Unbounded LTV Parameters in AdministrationSetters

AdministrationSetters.sol
W-18
WARNING
FIXED

No Pause Mechanism in Initialize

Initialize.sol
W-19
WARNING
ACKNOWLEDGED

Unfair fee collection on price increase in ApplyMaxGrowthFee

ApplyMaxGrowthFee.sol
W-20
WARNING
FIXED

Readonly reentrancy during the execution of lowLevel functions in ExecuteLowLevelRebalance

ExecuteLowLevelRebalance.sol
W-21
WARNING
ACKNOWLEDGED

Missing Protections Against Price Manipulation in Oracle Functions in AaveV3OracleConnector, MorphoOracleConnector

AaveV3OracleConnector.sol
MorphoOracleConnector.sol
W-22
WARNING
FIXED

Slippage value validation in ConstantSlippageConnector

ConstantSlippageConnector.sol
W-23
WARNING
ACKNOWLEDGED

Inability to deposit when borrow is negative in Vault, VaultCollateral

Vault.sol
VaultCollateral.sol
W-24
WARNING
FIXED

Missing handling of attempts to liquidate more collateral than available in OnlyEmergencyDeleverager

OnlyEmergencyDeleverager.sol
I-01
INFO
FIXED

Incorrect uint256 Type for eMode Parameter in AaveV3Connector

AaveV3Connector.sol
I-02
INFO
FIXED

Unsafe Use of abi.encodePacked for Hashing in WhitelistRegistry

WhitelistRegistry.sol
I-03
INFO
FIXED

Missing Minimum Value Enforcement for Auction Duration in Initialize

Initialize.sol
I-04
INFO
FIXED

No sweep of excessive tokens in LTV

LTV.sol
I-05
INFO
FIXED

Redundant parameter type in function _getBool in BoolReader

BoolReader.sol
I-06
INFO
ACKNOWLEDGED

feeCollector cannot burn shares when withdrawals are disabled in AdministrationSetters

AdministrationSetters.sol
I-07
INFO
FIXED

Misleading comments and typos in TotalAssets, TotalSupply, MaxGrowthFee, DeltaSharesAndDeltaRealBorrow, DeltaSharesAndDeltaRealCollateral

TotalSupply.sol
TotalAssets.sol
MaxGrowthFee.sol
DeltaSharesAndDeltaRealBorrow.sol
DeltaSharesAndDeltaRealCollateral.sol

Please select finding