Streaming Fund Management Vulnerability in Gardens v2 by 1Hive
CVE-2026-55658

7.7HIGH

Key Information:

Vendor

1hive

Vendor
CVE Published:
3 September 2026

What is CVE-2026-55658?

Gardens v2, a modular governance framework from 1Hive, suffers from a significant design flaw in its management of streaming proposals. When a proposal is funded, the necessary pool funds are transferred into an escrow account for a Superfluid constant flow agreement. However, the cancelProposal function fails to reclaim the escrow's balance once the proposal is canceled, allowing funds that should return to the pool to remain unaccounted for. The beneficiary of these funds is often the proposal submitter, and without a mechanism to reclaim these parked funds except for a rare dispute scenario, the vulnerability poses a financial risk to the governance framework. At present, no patches are publicly available to mitigate this issue.

Affected Version(s)

gardens-v2 <= 3e595f3

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.