github.com/MANTRA-Chain/mantrachain/x/tokenfactory tx gas limit is not enforced in send hooks
High severity
GitHub Reviewed
Published
Sep 30, 2025
in
MANTRA-Chain/mantrachain
•
Updated Oct 2, 2025
Description
Published to the GitHub Advisory Database
Sep 30, 2025
Reviewed
Sep 30, 2025
Published by the National Vulnerability Database
Oct 2, 2025
Last updated
Oct 2, 2025
Impact
send hooks can spend more gas than what's remained in tx, combined with recursive calls in the wasm contract, can amplify the gas consumption exponentially.
Patches
It's patched in v4.0.2 and v5.0.0
Workarounds
Is there a way for users to fix or remediate the vulnerability without upgrading?
References