Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-53924— Gardens v2: Permissionless syncOutflow bypasses streaming proposal disputes

Quick assessment

Affected
1Hive gardens-v2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Gardens v2 是一个模块化治理框架,允许社区创建和管理具有可定制参数和投票机制的多个治理池。在提交 之前, 方法在托管账户处于争议状态时能正确拒绝提现请求,但无需权限的 路径却执行了相同的超额余额转账操作,而未检查争议状态。当流式提案被质疑后,任何人均可调用 ,在争议尚未解决期间,将托管的 SuperTokens 转给提案受益人。如果该提案最终被否决,这些代币将无法通过 方法收回。此问题已在提交 中得到修复。

CVSS 8.7 · High

Possible ATT&CK Techniques 1 AI

T1595 · Active Scanning

Affected Version Matrix 1

VendorProduct Version RangeStatus
1Hive gardens-v2 < 0xc9d4e0dacd937364793278180551e59d93cd43f9 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-53924

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Gardens v2: Permissionless syncOutflow bypasses streaming proposal disputes
Source: CVE Program / CVE List V5
Vulnerability Description
Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. Prior to 0xc9d4e0dacd937364793278180551e59d93cd43f9, StreamingEscrow.claim() correctly rejects withdrawals while an escrow is disputed, but the permissionless syncOutflow() path performs the same excess-balance transfer without checking disputed. After a streaming proposal is challenged, anyone can call syncOutflow() to transfer escrowed SuperTokens to the proposal beneficiary while the dispute is pending. If the proposal is later rejected, those tokens cannot be recovered by drainToStrategy(). This issue has been patched in 0xc9d4e0dacd937364793278180551e59d93cd43f9.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
访问控制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
1Hive gardens-v2 < 0xc9d4e0dacd937364793278180551e59d93cd43f9 -

II. Public POCs for CVE-2026-53924

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-53924

登录查看更多情报信息。

Vendor Advisories for CVE-2026-53924 (1)

Same Patch Batch · 1Hive · 2026-09-03 · 3 CVEs total

CVE-2026-57445 8.7 HIGH Gardens v2: Approve-side dispute resolution drains active streaming escrow reserve
CVE-2026-55658 7.7 HIGH Gardens v2: StreamingEscrow buffer drains to the proposal beneficiary on cancel via the pe

IV. Related Vulnerabilities

V. Comments for CVE-2026-53924

No comments yet


Leave a comment