PT-2026-85061 · Unknown · Gardens-V2
CVE-2026-57445
·
Published
2026-09-03
·
Updated
2026-09-03
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Gardens v2 versions prior to dfba919e218e20d52db9f7b2e8d292d45a46c91b
Description
Gardens v2 is a modular governance framework used by communities to manage governance pools with customizable voting mechanisms and parameters. A flaw exists in the
StreamingEscrow component where the approve-side dispute resolution path allows the entire available escrow balance to be drained to the proposal beneficiary, failing to preserve the depositAmount() required for active stream escrow reserves.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gardens-V2