CVE-2026-28410

The Graph is an indexing protocol for querying networks like Ethereum, IPFS, Polygon, and other blockchains. Prior to version 3.0.0, a flaw in the token vesting contracts allows users to access tokens that should still be locked according to their vesting schedule. This issue has been patched in version 3.0.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:thegraph:graph_protocol_contracts:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-03-05 21:16

Updated : 2026-03-10 16:54


NVD link : CVE-2026-28410

Mitre link : CVE-2026-28410

CVE.ORG link : CVE-2026-28410


JSON object : View

Products Affected

thegraph

  • graph_protocol_contracts
CWE
CWE-284

Improper Access Control

CWE-682

Incorrect Calculation