From ce247708b51ee41fada4861f3a6ee221fe9c2956 Mon Sep 17 00:00:00 2001 From: Sasha Mitchell Date: Fri, 25 Sep 2026 17:44:02 +0700 Subject: [PATCH] Reject ABI booleans that are not 0 or 1. bool.decode treated every uint256 other than 1 as false, so a 2 decoded as false. Only 0 and 1 are valid. --- src/parsers/bool.test.ts | 9 +++++++++ src/parsers/bool.ts | 13 +++++++++++-- 2 files changed, 20 insertions(+), 2 deletions(-) diff --git a/src/parsers/bool.test.ts b/src/parsers/bool.test.ts index 5039162..27bae84 100644 --- a/src/parsers/bool.test.ts +++ b/src/parsers/bool.test.ts @@ -107,5 +107,14 @@ describe('boolean', () => { bool.decode({ type: 'bool', value: falseValue, skip: jest.fn() }), ).toBe(false); }); + + it('rejects a boolean that is not 0 or 1', () => { + const twoValue = hexToBytes( + '0000000000000000000000000000000000000000000000000000000000000002', + ); + expect(() => + bool.decode({ type: 'bool', value: twoValue, skip: jest.fn() }), + ).toThrow('Invalid boolean value. Expected 0 or 1, but received "2".'); + }); }); }); diff --git a/src/parsers/bool.ts b/src/parsers/bool.ts index e67678f..46bbf66 100644 --- a/src/parsers/bool.ts +++ b/src/parsers/bool.ts @@ -104,7 +104,16 @@ export const bool: Parser = { */ decode(args): boolean { // Booleans are encoded as 32-byte integers, so we use the number parser - // to decode the boolean value. - return number.decode({ ...args, type: 'uint256' }) === BigInt(1); + // to decode the boolean value. Only 0 and 1 are valid. + const decoded = number.decode({ ...args, type: 'uint256' }); + if (decoded === BigInt(0)) { + return false; + } + if (decoded === BigInt(1)) { + return true; + } + throw new ParserError( + `Invalid boolean value. Expected 0 or 1, but received "${decoded.toString()}".`, + ); }, };