Threat Advisory

Klever Flaw Enables Unbounded Minting of KLV

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in github., affecting versions prior to 1.7.19. The overall risk/impact is moderate to high due to potential exploitation of sensitive data and unbounded minting of KLV.

CVE-2026-54754 (CVSS 5.9 — Medium): A vulnerability in the marketplace settlement mints KLV when referral % + royalty % exceed the bid, allowing negative seller share silently skipped. An attacker with moderate capability can exploit this issue.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in github., affecting versions prior to 1.7.19. The overall risk/impact is moderate to high due to potential exploitation of sensitive data and unbounded minting of KLV.

CVE-2026-54754 (CVSS 5.9 — Medium): A vulnerability in the marketplace settlement mints KLV when referral % + royalty % exceed the bid, allowing negative seller share silently skipped. An attacker with moderate capability can exploit this issue.[emaillocker id="1283"]

CVE-2026-54755: An integer overflow in split-royalty validation enables unbounded minting of KLV (native token).

RECOMMENDATION:

We recommend you to update github.com/klever-io/klever-go to version 1.7.19.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu