Vulnerability Description
Smart contract Marginal v1 performs unsafe downcast, allowing attackers to settle a large debt position for a negligible asset cost.
CVSS Score
8.6
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Marginal | V1-Core | <= 1.0.2 |
Related Weaknesses (CWE)
References
- https://cvefeed.io/cwe/detail/cwe-681-incorrect-conversion-between-numeric-typesNot Applicable
- https://github.com/MarginalProtocolProduct
- https://marginal.gitbook.io/docsProduct
- https://medium.com/@clarkcorrin/cve-2026-4931-how-spearbits-cantina-denied-a-criMitigationPress/Media CoverageThird Party Advisory
- https://scs.owasp.org/SCWE/SCSVS-CODE/SCWE-041/Not Applicable
FAQ
What is CVE-2026-4931?
CVE-2026-4931 is a vulnerability with a CVSS score of 8.6 (HIGH). Smart contract Marginal v1 performs unsafe downcast, allowing attackers to settle a large debt position for a negligible asset cost.
How severe is CVE-2026-4931?
CVE-2026-4931 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-4931?
Check the references section above for vendor advisories and patch information. Affected products include: Marginal V1-Core.