CVE-2025-61595: github.com/MANTRA-Chain/mantrachain/x/tokenfactory tx gas limit is not enforced in send hooks
(updated )
send hooks can spend more gas than what’s remained in tx, combined with recursive calls in the wasm contract, can amplify the gas consumption exponentially.
References
- github.com/MANTRA-Chain/mantrachain
- github.com/MANTRA-Chain/mantrachain/commit/30d36c46e9823b56b8f0dcbb66e980ca5df284e4
- github.com/MANTRA-Chain/mantrachain/issues/432
- github.com/MANTRA-Chain/mantrachain/security/advisories/GHSA-qwvm-wqq8-8j69
- github.com/advisories/GHSA-qwvm-wqq8-8j69
- nvd.nist.gov/vuln/detail/CVE-2025-61595
Code Behaviors & Features
Detect and mitigate CVE-2025-61595 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →