Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qwvm-wqq8-8j69

Опубликовано: 30 сент. 2025
Источник: github
Github: Прошло ревью
CVSS4: 8.8

Описание

github.com/MANTRA-Chain/mantrachain/x/tokenfactory tx gas limit is not enforced in send hooks

Impact

send hooks can spend more gas than what's remained in tx, combined with recursive calls in the wasm contract, can amplify the gas consumption exponentially.

Patches

It's patched in v4.0.2 and v5.0.0

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading?

Пакеты

Наименование

github.com/MANTRA-Chain/mantrachain/v4

go
Затронутые версииВерсия исправления

< 4.0.2

4.0.2

Наименование

github.com/MANTRA-Chain/mantrachain/v3

go
Затронутые версииВерсия исправления

Отсутствует

Наименование

github.com/MANTRA-Chain/mantrachain/v2

go
Затронутые версииВерсия исправления

Отсутствует

Наименование

github.com/MANTRA-Chain/mantrachain

go
Затронутые версииВерсия исправления

Отсутствует

EPSS

Процентиль: 20%
0.00063
Низкий

8.8 High

CVSS4

Дефекты

CWE-400
CWE-770

Связанные уязвимости

nvd
4 месяца назад

MANTRA is a purpose-built RWA Layer 1 Blockchain, capable of adherence to real world regulatory requirements. Versions 4.0.1 and below do not enforce the tx gas limit in its send hooks. Send hooks can spend more gas than what remains in tx, combined with recursive calls in the wasm contract, potentially amplifying the gas consumption exponentially. This is fixed in version 4.0.2.

EPSS

Процентиль: 20%
0.00063
Низкий

8.8 High

CVSS4

Дефекты

CWE-400
CWE-770