Mantra · Mantra · CVE-2025-61595
**Name of the Vulnerable Software and Affected Versions**
MANTRA versions prior to 4.0.2
**Description**
The software does not enforce transaction gas limits within its send hooks. This allows send hooks to consume more gas than available in the transaction, and recursive calls within the WebAssembly (Wasm) contract can exponentially increase gas consumption. This issue affects a purpose-built Real World Asset (RWA) Layer 1 Blockchain designed to adhere to real-world regulatory requirements.
**Recommendations**
Upgrade to version 4.0.2 or later.