Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-55658— Gardens v2: StreamingEscrow buffer drains to the proposal beneficiary on cancel via the permissionless claim()

Quick assessment

Affected
1Hive gardens-v2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Gardens v2 是一个模块化治理框架,使社区能够创建和管理具有可定制参数和投票机制的多个治理池。在版本 3e595f3 及更早版本中,当流式提案获得资金时,流式合约集群会将真实的资金池资金转入该提案的 StreamingEscrow(流式托管),用于支撑超级流式常流协议(包括 CFA 存款以及 0.5% 的保证金)。 函数会将托管合约中的 GDA 成员份额清零,但从未追回已停放的余额;而无需授权的 函数会将托管合约的整个余额(包括资金池的资金缓冲)转给受益人。该受益人由提案提交者选定,默认即为提交者本身。唯一

CVSS 7.7 · High

Possible ATT&CK Techniques 2 AI

T1019 T1529 · System Shutdown/Reboot

Affected Version Matrix 1

VendorProduct Version RangeStatus
1Hive gardens-v2 <= 3e595f3 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-55658

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Gardens v2: StreamingEscrow buffer drains to the proposal beneficiary on cancel via the permissionless claim()
Source: CVE Program / CVE List V5
Vulnerability Description
Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In 3e595f3 and prior, when a streaming proposal is funded, the cluster of streaming contracts moves real pool funds into the proposal's StreamingEscrow to back the Superfluid constant flow agreement (the CFA deposit, plus a 0.5 percent margin). cancelProposal then zeroes the escrow's GDA member units but never reclaims that parked balance, and the permissionless claim() forwards the escrow's entire balance, including the pool funded buffer, to the beneficiary. The beneficiary is chosen by the proposal submitter and defaults to the submitter. The only path that returns escrow funds to the pool is drainToStrategy, which is onlyStrategy and is reached solely from the dispute reject ruling, never from cancel or natural completion. At time of publication, there are no publicly known patches.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
1Hive gardens-v2 <= 3e595f3 -

II. Public POCs for CVE-2026-55658

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-55658

登录查看更多情报信息。

Vendor Advisories for CVE-2026-55658 (1)

Same Patch Batch · 1Hive · 2026-09-03 · 3 CVEs total

CVE-2026-53924 8.7 HIGH Gardens v2: Permissionless syncOutflow bypasses streaming proposal disputes
CVE-2026-57445 8.7 HIGH Gardens v2: Approve-side dispute resolution drains active streaming escrow reserve

IV. Related Vulnerabilities

V. Comments for CVE-2026-55658

No comments yet


Leave a comment