Streaming Fund Management Vulnerability in Gardens v2 by 1Hive
CVE-2026-55658
What is CVE-2026-55658?
Gardens v2, a modular governance framework from 1Hive, suffers from a significant design flaw in its management of streaming proposals. When a proposal is funded, the necessary pool funds are transferred into an escrow account for a Superfluid constant flow agreement. However, the cancelProposal function fails to reclaim the escrow's balance once the proposal is canceled, allowing funds that should return to the pool to remain unaccounted for. The beneficiary of these funds is often the proposal submitter, and without a mechanism to reclaim these parked funds except for a rare dispute scenario, the vulnerability poses a financial risk to the governance framework. At present, no patches are publicly available to mitigate this issue.
Affected Version(s)
gardens-v2 <= 3e595f3
