High-Severity Flaw in Lean 4 Kernel Allows Proving 0=1

jedisct1 · x · 2026-08-12

Security researchers uncovered a type confusion vulnerability (CWE-843) in the Lean 4 theorem prover kernel. By bypassing projection validation in nested inductive types, an attacker can exploit a crafted hash collision to make the system accept a proof of False, ultimately deriving 0 = 1.

Tracked as CVSS 7.1 High severity, the flaw affects Lean 4 v4.31.0 and earlier. The developers have addressed the issue in recent nightly builds, and an axiom-free Proof of Concept (PoC) has been published.

Original post →

More from Safety

Safety channel →