PT-2026-85059 · Garden · Garden
CVE-2026-53924
·
Published
2026-09-03
·
Updated
2026-09-03
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Gardens v2 versions prior to 0xc9d4e0dacd937364793278180551e59d93cd43f9
Description
A flaw exists in the modular governance framework where the permissionless
syncOutflow() function fails to check if an escrow is disputed before performing an excess-balance transfer. While the claim() function in StreamingEscrow correctly rejects withdrawals during a dispute, the syncOutflow() path allows anyone to transfer escrowed SuperTokens to a proposal beneficiary while a dispute is pending. If the proposal is subsequently rejected, the tokens cannot be recovered via the drainToStrategy() function.Recommendations
Update to version 0xc9d4e0dacd937364793278180551e59d93cd43f9.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Garden