PT-2026-23505 · Graphprotocol · The Graph
Published
2026-03-05
·
Updated
2026-03-10
·
CVE-2026-28410
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
The Graph versions prior to 3.0.0
Description
A flaw exists in the token vesting contracts of The Graph protocol. This issue allows users to access tokens before they are released according to their vesting schedule. The problem was addressed with the release of version 3.0.0.
Recommendations
Update to version 3.0.0 or later.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
The Graph