Vulnerability in Gardens v2 Governance Framework by 1Hive
CVE-2026-53924
8.7HIGH
What is CVE-2026-53924?
The Gardens v2 governance framework by 1Hive contains a vulnerability that allows unauthorized transfers of escrowed SuperTokens during a pending dispute. While the StreamingEscrow.claim() function correctly rejects withdrawals when an escrow is disputed, the syncOutflow() method lacks similar validation. This oversight allows any party to initiate a transfer of tokens to a proposal beneficiary while the proposal is under dispute. If the proposal is ultimately rejected, those tokens become irrecoverable, posing significant security risks to the governance process. A patch addressing this issue is available in the latest release.
Affected Version(s)
gardens-v2 < 0xc9d4e0dacd937364793278180551e59d93cd43f9
