VulnerabilityAnalyzed
CVE-2026-4931
Smart contract Marginal v1 performs unsafe downcast, allowing attackers to settle a large debt position for a negligible asset cost.
HIGH 8.6EPSS 0.26%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.26%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Smart contract Marginal v1 performs unsafe downcast, allowing attackers to settle a large debt position for a negligible asset cost.
- CVSS 3.1
- 8.6 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
- EPSS
- 0.26% probability · 17th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-681
- Affected
- marginal/v1-core
- Source
- cret@cert.org
References
- https://cvefeed.io/cwe/detail/cwe-681-incorrect-conversion-between-numeric-typesNot Applicable
- https://github.com/MarginalProtocolProduct
- https://marginal.gitbook.io/docsProduct
- https://medium.com/@clarkcorrin/cve-2026-4931-how-spearbits-cantina-denied-a-critical-vulnerability-using-verifiably-false-0a27b92ac2dbMitigation, Press/Media Coverage, Third Party Advisory
- https://scs.owasp.org/SCWE/SCSVS-CODE/SCWE-041/Not Applicable
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.