FlawAtlas
Search the atlas
CVE-2025-61595 High

github.com/MANTRA-Chain/mantrachain/x/tokenfactory tx gas limit is not enforced in send hooks in github.com/MANTRA-Chain/mantrachain

github.com/MANTRA-Chain/mantrachain/x/tokenfactory tx gas limit is not enforced in send hooks in github.com/MANTRA-Chain/mantrachain

Exploit probability 0.3%
Published October 23, 2025
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

16 explicit affected versions

Go github.com/MANTRA-Chain/mantrachain
Go github.com/MANTRA-Chain/mantrachain/v2
Go github.com/MANTRA-Chain/mantrachain/v3
Go github.com/MANTRA-Chain/mantrachain/v4
Go github.com/MANTRA-Chain/mantrachain
Go github.com/MANTRA-Chain/mantrachain/v2
Go github.com/MANTRA-Chain/mantrachain/v3
Go github.com/MANTRA-Chain/mantrachain/v4

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2026:21483-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2025-61595

MANTRA is a purpose-built RWA Layer 1 Blockchain, capable of adherence to real world regulatory requirements. Versions 4.0.1 and below do not enforce the tx gas limit in its send hooks. Send hooks can spend more gas than what remains in tx, combined with recursive calls in the wasm contract, potentially amplifying the gas consumption exponentially. This is fixed in version 4.0.2.

View original source
Open Source Vulnerabilities GO-2025-3997

github.com/MANTRA-Chain/mantrachain/x/tokenfactory tx gas limit is not enforced in send hooks in github.com/MANTRA-Chain/mantrachain

View original source
Open Source Vulnerabilities GHSA-qwvm-wqq8-8j69

### Impact send hooks can spend more gas than what's remained in tx, combined with recursive calls in the wasm contract, can amplify the gas consumption exponentially. ### Patches It's patched in v4.0.2 and v5.0.0 ### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_

View original source

05 / REFERENCES

Further evidence