Multiple security vulnerabilities have been identified in github., affecting versions prior to 1.7.19. The overall risk/impact is moderate to high due to potential exploitation of sensitive data and unbounded minting of KLV.
CVE-2026-54754 (CVSS 5.9 — Medium): A vulnerability in the marketplace settlement mints KLV when referral % + royalty % exceed the bid, allowing negative seller share silently skipped. An attacker with moderate capability can exploit this issue.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in github., affecting versions prior to 1.7.19. The overall risk/impact is moderate to high due to potential exploitation of sensitive data and unbounded minting of KLV.
CVE-2026-54754 (CVSS 5.9 — Medium): A vulnerability in the marketplace settlement mints KLV when referral % + royalty % exceed the bid, allowing negative seller share silently skipped. An attacker with moderate capability can exploit this issue.[emaillocker id="1283"]
CVE-2026-54755: An integer overflow in split-royalty validation enables unbounded minting of KLV (native token).
We recommend you to update github.com/klever-io/klever-go to version 1.7.19.
The following reports contain further technical details:
[/emaillocker]