THREAT OPS › Threat News › [GHSA] GHSA-p7gw-2pcp-5pf8 (critical) — Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped)
[GHSA] GHSA-p7gw-2pcp-5pf8 (critical) — Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped)
GHSA-p7gw-2pcp-5pf8 Severity: critical CVE: CVE-2026-54754
Klever: Marketplace settlement mints KLV when referral % + royalty % exceed the bid (negative seller share silently skipped)
## Summary
When a marketplace order is settled (`MarketBuy` / `BuyItNow`, and auction `Claim`), the buyer's payment is split three ways — **referral**, **royalties**, and the **seller (market-order owner) remainde
Indicators of compromise
- 54ea28e527d4136508be955374afa54a8c25c19a48c674f412f7ce02db0f4e1bsha256
- bb687dbba23e1844fec674a32cb8809f0d3207506c53fc3d637e40dc56708d63sha256
- 77388d3dfe6cd88e8da723254c11abf3d9cccb6fb77b000e5038fc3ff92b964dsha256
- a196789b026f996867f08317cc6c5a4eb9ad3a59b1be3716420bc8692d4c3048sha256
- CVE-2026-54754cve
- https://kpulse.tech)**url
Original source: https://github.com/advisories/GHSA-p7gw-2pcp-5pf8