Arbitrary call with user-controlled target
Liquid Collective (LsETH)'s assessment for RD-F-013 — scored green on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.
Evidence summary #
Source inspection found no arbitrary .call(target, data) where target is user-supplied. External calls in River.1.sol target fixed state-variable addresses retrieved via getter functions (RedeemManagerAddress.get(), ELFeeRecipientAddress.get()). No user-controlled call targets found.
Sources #
- GitHubRiver.1.sol — Liquid CollectiveRiver.1.sol — all external calls target fixed contract addresses from stateretrieved 2026-05-17
Methodology #
Determine whether any contract performs `.call(target, data)` where target and/or data is user-supplied without a target allowlist or selector filter.
See the full factor methodology and distribution across all protocols →
rubric_version v1.7.0 protocol liquid-collective factor RD-F-013 score green collected_at 2026-05-16 19:46:23