PT-2026-85059 · Garden · Garden

CVE-2026-53924

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Gardens v2 versions prior to 0xc9d4e0dacd937364793278180551e59d93cd43f9
Description A flaw exists in the modular governance framework where the permissionless syncOutflow() function fails to check if an escrow is disputed before performing an excess-balance transfer. While the claim() function in StreamingEscrow correctly rejects withdrawals during a dispute, the syncOutflow() path allows anyone to transfer escrowed SuperTokens to a proposal beneficiary while a dispute is pending. If the proposal is subsequently rejected, the tokens cannot be recovered via the drainToStrategy() function.
Recommendations Update to version 0xc9d4e0dacd937364793278180551e59d93cd43f9.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53924

Affected Products

Garden