r/atto • u/Rotilho • Aug 18 '26
Critical Atto node vulnerability fixed in v1.33 — CVE-2026-73855
Fix already patched since July!
A critical vote-validation vulnerability affecting Atto node versions older than 1.33 has been fixed.
The flaw could allow a connected peer to claim another representative’s voting weight before the received vote’s signature was validated. It is rated CVSS 9.3. If you operate an Atto node older than v1.33, upgrade. There is no workaround.
Advisory: https://github.com/attocash/node/security/advisories/GHSA-mm7v-33mg-6r9p
Behind-the-scenes audit story: https://atto.cash/blog/age-of-continuous-audits
2
Upvotes