Description
Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. The spendable balance is not updated properly when delegating vested tokens. The issue allows a clawback vesting account to anticipate the release of unvested tokens. This vulnerability is fixed in 18.0.0.
Published: 2024-06-06
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-2129 Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. The spendable balance is not updated properly when delegating vested tokens. The issue allows a clawback vesting account to anticipate the release of unvested tokens. This vulnerability is fixed in 18.0.0.
Github GHSA Github GHSA GHSA-pxv8-qhrh-jc7v evmos allows transferring unvested tokens after delegations
History

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00121}

epss

{'score': 0.00174}


Tue, 15 Oct 2024 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Evmos
Evmos evmos
CPEs cpe:2.3:a:evmos:evmos:*:*:*:*:*:*:*:*
Vendors & Products Evmos
Evmos evmos

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T02:20:35.599Z

Reserved: 2024-04-19T14:07:11.229Z

Link: CVE-2024-32873

cve-icon Vulnrichment

Updated: 2024-06-07T13:52:58.755Z

cve-icon NVD

Status : Modified

Published: 2024-06-06T19:15:56.390

Modified: 2024-11-21T09:15:54.657

Link: CVE-2024-32873

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses