๐Ÿ” CVE Alert

CVE-2026-53924

UNKNOWN 0.0

Gardens v2: Permissionless syncOutflow bypasses streaming proposal disputes

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. Prior to 0xc9d4e0dacd937364793278180551e59d93cd43f9, StreamingEscrow.claim() correctly rejects withdrawals while an escrow is disputed, but the permissionless syncOutflow() path performs the same excess-balance transfer without checking disputed. After a streaming proposal is challenged, anyone can call syncOutflow() to transfer escrowed SuperTokens to the proposal beneficiary while the dispute is pending. If the proposal is later rejected, those tokens cannot be recovered by drainToStrategy(). This issue has been patched in 0xc9d4e0dacd937364793278180551e59d93cd43f9.

CWE CWE-284
Vendor 1hive
Product gardens-v2
Published Sep 3, 2026
Last Updated Sep 3, 2026
Stay Ahead of the Next One

Get instant alerts for 1hive gardens-v2

Be the first to know when new unknown vulnerabilities affecting 1hive gardens-v2 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

1Hive / gardens-v2
< 0xc9d4e0dacd937364793278180551e59d93cd43f9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/1Hive/gardens-v2/security/advisories/GHSA-jxgc-cgfq-436j