Category: Coding Mistakes
Missing Pricer Setter in IUSPCHub
Low Impact
Low Severity
Medium Likelihood
Description
The pricer address is configured only at initialization, and the contract lacks a mechanism to update it subsequently.
Impact
If the existing pricer contract malfunctions or requires replacement, there is no mechanism to update it. This creates a risk of the protocol relying on incorrect price feeds.
Recommendations
We recommend to add a privileged function to allow updating the pricer contract address.
Remediation
This issue has been acknowledged by Coinshift, and a fix was implemented in commit d14d8915↗.