{"schema_version":"1.7.3","id":"GHSA-qwvm-wqq8-8j69","published":"2025-09-30T21:06:02Z","modified":"2025-10-23T20:34:29Z","aliases":["CVE-2025-61595","GO-2025-3997"],"summary":"github.com/MANTRA-Chain/mantrachain/x/tokenfactory tx gas limit is not enforced in send hooks","details":"### Impact\n\nsend hooks can spend more gas than what's remained in tx, combined with recursive calls in the wasm contract, can amplify the gas consumption exponentially.\n\n### Patches\n\nIt's patched in v4.0.2 and v5.0.0\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_","affected":[{"package":{"name":"github.com/MANTRA-Chain/mantrachain/v4","ecosystem":"Go","purl":"pkg:golang/github.com/MANTRA-Chain/mantrachain/v4"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.0.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-qwvm-wqq8-8j69/GHSA-qwvm-wqq8-8j69.json"}},{"package":{"name":"github.com/MANTRA-Chain/mantrachain/v3","ecosystem":"Go","purl":"pkg:golang/github.com/MANTRA-Chain/mantrachain/v3"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"database_specific":{"last_known_affected_version_range":"< 4.0.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-qwvm-wqq8-8j69/GHSA-qwvm-wqq8-8j69.json"}},{"package":{"name":"github.com/MANTRA-Chain/mantrachain/v2","ecosystem":"Go","purl":"pkg:golang/github.com/MANTRA-Chain/mantrachain/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"database_specific":{"last_known_affected_version_range":"< 4.0.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-qwvm-wqq8-8j69/GHSA-qwvm-wqq8-8j69.json"}},{"package":{"name":"github.com/MANTRA-Chain/mantrachain","ecosystem":"Go","purl":"pkg:golang/github.com/MANTRA-Chain/mantrachain"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"database_specific":{"last_known_affected_version_range":"< 4.0.2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-qwvm-wqq8-8j69/GHSA-qwvm-wqq8-8j69.json"}}],"references":[{"type":"WEB","url":"https://github.com/MANTRA-Chain/mantrachain/security/advisories/GHSA-qwvm-wqq8-8j69"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-61595"},{"type":"WEB","url":"https://github.com/MANTRA-Chain/mantrachain/issues/432"},{"type":"WEB","url":"https://github.com/MANTRA-Chain/mantrachain/commit/30d36c46e9823b56b8f0dcbb66e980ca5df284e4"},{"type":"PACKAGE","url":"https://github.com/MANTRA-Chain/mantrachain"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2025-3997"}],"database_specific":{"cwe_ids":["CWE-400","CWE-770"],"github_reviewed":true,"github_reviewed_at":"2025-09-30T21:06:02Z","nvd_published_at":"2025-10-02T20:15:35Z","severity":"HIGH"},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N"}]}