Vulnerability Description
Smart contract Marginal v1 performs unsafe downcast, allowing attackers to settle a large debt position for a negligible asset cost.
CVSS Score
6.8
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
Related Weaknesses (CWE)
References
- https://cvefeed.io/cwe/detail/cwe-681-incorrect-conversion-between-numeric-types
- https://github.com/MarginalProtocol
- https://marginal.gitbook.io/docs
- https://medium.com/@clarkcorrin/cve-2026-4931-how-spearbits-cantina-denied-a-cri
- https://scs.owasp.org/SCWE/SCSVS-CODE/SCWE-041/
FAQ
What is CVE-2026-4931?
CVE-2026-4931 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Smart contract Marginal v1 performs unsafe downcast, allowing attackers to settle a large debt position for a negligible asset cost.
How severe is CVE-2026-4931?
CVE-2026-4931 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-4931?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.