Junglewise Threat Intelligence

CVE-2026-4931: Marginal Protocol v1 unsafe downcast in smart contracts

CVE-2026-4931 · Severity: medium · CVSS 6.8 · Published 2026-04-07

Executive brief

Marginal v1, a decentralized finance protocol for leveraged trading, contains a flaw in its smart contract logic. An attacker can exploit this vulnerability to settle large debt positions for a fraction of their actual cost. This could lead to significant financial loss for the protocol's liquidity providers and damage the platform's reputation.

Technical details

The Marginal v1-core smart contracts contain an unsafe downcasting vulnerability (CWE-681). When converting between numeric types (e.g., from a larger integer type to a smaller one), the protocol fails to validate that the value fits within the destination type's range. This truncation allows an attacker to manipulate debt settlement calculations. Specifically, a large debt value can be downcast into a much smaller value, enabling the attacker to close out significant positions for a negligible cost. The vulnerability is located in the core settlement logic and can be triggered by any network participant interacting with the contract.

Affected products

  • Marginal Protocol v1-core up to (including) 1.0.2

Timeline

  • 2026-04-07: disclosed: Initial CVE publication
  • 2026-05-22: advisory: NVD analysis and enrichment completed

References