THREAT OPS › Threat News › [GHSA] GHSA-5gmm-hjfj-8ff7 (medium) — Paymenter has a credit-refund double-spend race condition in service downgrade (doUpgrade)
[GHSA] GHSA-5gmm-hjfj-8ff7 (medium) — Paymenter has a credit-refund double-spend race condition in service downgrade (doUpgrade)
GHSA-5gmm-hjfj-8ff7 Severity: medium CVE: CVE-2026-71537
Paymenter has a credit-refund double-spend race condition in service downgrade (doUpgrade)
### Summary
The service downgrade implementation in `app/Livewire/Services/Upgrade.php::doUpgrade()` executes a proration calculation and a subsequent user credit refund without any transactional safety or database locks. The only concurrency check
Indicators of compromise
- CVE-2026-71537cve
Original source: https://github.com/advisories/GHSA-5gmm-hjfj-8ff7