PT-2026-97525 · Klever-Go · Klever-Go
CVE-2026-82406
·
Published
2026-09-23
·
Updated
2026-09-24
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Klever-Go versions prior to 1.7.20
Description
The native marketplace implementation contains a logic error where the
Buy() function in core/kapp/market/market.go fails to verify the IsClaimed status of an order. This allows a seller to settle a resting-bid auction early via the Claim() function, which marks the order as claimed and delivers the NFT but fails to reset the EndTime or delete the order, creating a zombie order that appears active.A subsequent bidder can call the
Buy() function on this zombie order. The bidder is debited their bid amount, and the previous bidder (who could be the attacker) receives a refund. However, because the order is already marked as claimed, the new bidder cannot use Claim() or CancelOrder() to retrieve the NFT or recover their funds, leading to permanent loss of funds and potential theft by the attacker.Recommendations
Update to version 1.7.20.
As a temporary mitigation, avoid using the
Buy() function for orders that have already been settled or claimed.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Klever-Go