Impact
Gardens v2 is a modular governance framework that manages multiple governance pools with customizable voting. In versions up to and including the referenced commit, the approve‑side dispute resolution path can drain the entire available escrow balance to the proposal beneficiary, bypassing the intended partial reserve split. This logic flaw (CWE‑703) allows an attacker who can trigger dispute resolution on an active stream to deplete funds that should remain reserved for the beneficiary, resulting in loss of escrowed assets and financial loss to the community.
Affected Systems
The affected product is 1Hive Gardens v2, the modular governance framework for decentralized communities. No specific version range is listed; all instances that include the vulnerable approve‑side dispute resolution logic are impacted.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. EPSS is not available, and the vulnerability is not yet listed in CISA KEV. The exploit requires the ability to invoke the approve‑side dispute resolution on an active stream, which typically involves holding the approve role or compromising it. Since the vulnerability manipulates internal reserve accounting logic, it is a purely local logic flaw that does not expose an external network interface; therefore, the attack vector is inferred to be a privileged account or compromised operator.
OpenCVE Enrichment