PT-2026-97525 · Klever-Go · Klever-Go

CVE-2026-82406

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Klever-Go versions prior to 1.7.20
Description The native marketplace implementation contains a logic error where the Buy() function in core/kapp/market/market.go fails to verify the IsClaimed status of an order. This allows a seller to settle a resting-bid auction early via the Claim() function, which marks the order as claimed and delivers the NFT but fails to reset the EndTime or delete the order, creating a zombie order that appears active.
A subsequent bidder can call the Buy() function on this zombie order. The bidder is debited their bid amount, and the previous bidder (who could be the attacker) receives a refund. However, because the order is already marked as claimed, the new bidder cannot use Claim() or CancelOrder() to retrieve the NFT or recover their funds, leading to permanent loss of funds and potential theft by the attacker.
Recommendations Update to version 1.7.20. As a temporary mitigation, avoid using the Buy() function for orders that have already been settled or claimed.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82406
GHSA-26R5-4MM2-PX5C

Affected Products

Klever-Go