-
CVSS Score
-The vulnerabilities stem from upstream dependencies (IBC-Go and Cosmos SDK). The IBC-Go vulnerability (GHSA-4wf3-5qj9-368v) explicitly involves non-deterministic JSON unmarshalling in acknowledgement handling, which occurs in the channel module. The Cosmos SDK vulnerability (GHSA-47ww-ff84-4jrg) directly references the x/group module's EndBlocker function. The cheqd-node upgrade patched these by updating to ibc-go v7.10.0 and cosmos-sdk v0.47.17, confirming these functions were the root cause.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/cheqd/cheqd-node | go | < 3.1.8 | 3.1.8 |
A Semantic Attack on Google Gemini - Read the Latest Research