CVE-2026-4931

Smart contract Marginal v1 performs unsafe downcast, allowing attackers to settle a large debt position for a negligible asset cost.
Configurations

Configuration 1 (hide)

cpe:2.3:a:marginal:v1-core:*:*:*:*:*:*:*:*

History

22 May 2026, 18:51

Type Values Removed Values Added
CPE cpe:2.3:a:marginal:v1-core:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 6.8
v2 : unknown
v3 : 8.6
First Time Marginal
Marginal v1-core
References () https://cvefeed.io/cwe/detail/cwe-681-incorrect-conversion-between-numeric-types - () https://cvefeed.io/cwe/detail/cwe-681-incorrect-conversion-between-numeric-types - Not Applicable
References () https://github.com/MarginalProtocol - () https://github.com/MarginalProtocol - Product
References () https://marginal.gitbook.io/docs - () https://marginal.gitbook.io/docs - Product
References () https://medium.com/@clarkcorrin/cve-2026-4931-how-spearbits-cantina-denied-a-critical-vulnerability-using-verifiably-false-0a27b92ac2db - () https://medium.com/@clarkcorrin/cve-2026-4931-how-spearbits-cantina-denied-a-critical-vulnerability-using-verifiably-false-0a27b92ac2db - Mitigation, Press/Media Coverage, Third Party Advisory
References () https://scs.owasp.org/SCWE/SCSVS-CODE/SCWE-041/ - () https://scs.owasp.org/SCWE/SCSVS-CODE/SCWE-041/ - Not Applicable

08 Apr 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8
CWE CWE-681

07 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-07 16:16

Updated : 2026-05-22 18:51


NVD link : CVE-2026-4931

Mitre link : CVE-2026-4931

CVE.ORG link : CVE-2026-4931


JSON object : View

Products Affected

marginal

  • v1-core
CWE
CWE-681

Incorrect Conversion between Numeric Types