CVE-2026-28410
The Graph: Revocable vesting contracts allows early access to locked tokens
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Graph is an indexing protocol for querying networks like Ethereum, IPFS, Polygon, and other blockchains. Prior to version 3.0.0, a flaw in the token vesting contracts allows users to access tokens that should still be locked according to their vesting schedule. This issue has been patched in version 3.0.0.
| CWE | CWE-284 CWE-682 |
| Vendor | graphprotocol |
| Product | contracts |
| Published | Mar 5, 2026 |
| Last Updated | Mar 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for graphprotocol contracts
Be the first to know when new unknown vulnerabilities affecting graphprotocol contracts are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
graphprotocol / contracts
< 3.0.0