- All findings
- 2
- Critical
- 1
- High
- 1
- Medium
- 0
- Low
- 0
- Informational
- 0
Date of engagement: 10th December 2025 - 29th December 2025
About Us
Guvenkaya is a security research firm specializing in Rust security, Web3 security of Non-EVM protocols, and Web2 security. With our expertise, we provide both security auditing services and custom security solutions
About Sailor Lend
Sailor Lend is a trustless, self-custodial DeFi lending protocol built on the NEAR blockchain. The platform enables users to obtain instant loans using BTC, ZEC, or SOL as collateral without requiring KYC verification. Users can deposit stablecoins for lending to earn interest, while borrowers can leverage their crypto assets to access liquidity. The protocol implements liquidation mechanisms, interest rate calculations, and Pyth price oracle integrations.
Audit Results
Guvenkaya conducted a comprehensive security assessment of the Sailor Lend web application. During this engagement, 2 findings were reported: 1 Critical and 1 High severity issue. The critical finding includes a remote code execution vulnerability through React2Shell (CVE-2025-55182) affecting React Server Components. All findings have been addressed by the Sailor Lend team.
Project Scope
Sailor Lend Web Application
| Files | Link |
|---|---|
| Sailor Lend Web Application | https://github.com/Satoshi-Port/satoshi-port/tree/93fbf4f33c97999cb74ff109f355b6c73bc722f8/src |
Out of Scope
The audit included reviewing the code for security vulnerabilities, coding practices, and architecture. The audit does not include a review of the dependencies or external contracts such as Pyth Oracle and FT contracts.
Timeline
- Start of the audit
10th December 2025
- Draft report
29th December 2025
- Final report
17th March 2026
Methodology
- RESEARCH INTO PROJECT ARCHITECTURE
- PREPARING ATTACK VECTORS
- SETTING UP AN ENVIRONMENT
- MANUAL CODE REVIEW OF THE CODE
- ASSESSMENT OF WEB APPLICATION SECURITY ISSUES
- ASSESSMENT OF ARITHMETIC ISSUES
- BUSINESS LOGIC VULNERABILITY ASSESSMENT
Severity Breakdown
Findings Summary
| Finding | Impact | Likelihood | Severity | Remediation complexity | Remediation status |
|---|---|---|---|---|---|
| GUV-1: Vulnerable to React2Shell | Severe | Likely | Critical | Simple | Fixed |
| GUV-2: Hardcoded Password in Source Code | Moderate | Likely | High | Simple | Fixed |
Findings Details
GUV-1: Vulnerable to React2Shell
CriticalThe application is vulnerable to React2Shell (CVE-2025-55182), a critical remote code execution (RCE) vulnerability affecting React Server Components. The project currently uses React 19.0.0, which falls within the vulnerable version range (19.0.0 through 19.2.0).
This vulnerability stems from unsafe deserialization within React's "Flight" protocol, allowing unauthenticated attackers to execute arbitrary code on the server by sending specially crafted HTTP requests. The application uses Next.js 15.1.4 with the App Router, which relies on React Server Components and is therefore affected.
The vulnerability was confirmed using https://github.com/assetnote/react2shell-scanner tool.
Recommendation
We recommend updating the react version to a non-vulnerable version.
Remediation - Fixed
Sailor Lend team has fixed this issue in commit 3446235a0abc82377a266bc8c8a056c3523130fc
GUV-2: Hardcoded Password in Source Code
HighThe source code contains a hardcoded password that is checked before accessing the web application.
Password Check
const passwordIsCorrect = (value: string) => {
return value === "satoshi";
};Recommendation
We recommend avoiding hard-coding sensitive values in the code. The best approach would be to send the password to the backend and do the hash-based comparison there.
Remediation - Fixed
Sailor Lend team has fixed this issue in commit 3446235a0abc82377a266bc8c8a056c3523130fc
Source: published GitHub report · 12 pages. The original PDF includes the source formatting, figures, and linked references.

