SCA: security update for github.com/ixofoundation/ixo-blockchain, github.com/ixofoundation/ixo-blockchain/v3, github.com/ixofoundation/ixo-blockchain/v4, github.com/ixofoundation/ixo-blockchain/v5, github.com/ixofoundation/ixo-blockchain/v6, github.com/ixofoundation/ixo-blockchain/v7, github.com/ixofoundation/ixo-blockchain/v8 (GHSA-w3rp-4cm2-4wgc)

critical Tenable Self-Hosted Container Security Plugin ID 448344

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet. Prior to version 8.0.0,
the x/bonds module moved funds from an address that was resolved from a DID verification method, without
verifying that the resolved address belonged to the transaction signer. Affected handlers included
MsgMakeOutcomePayment, MsgBuy, MsgSell, MsgSwap, and MsgWithdrawShare, as well as the batch order
processor. Because any account may list an arbitrary blockchainAccountID as a verification method on a DID
it controls (without the consent of that address's owner), an attacker could register victims' addresses
as verification methods on their own DID and then move the victims' balances into a bond the attacker
controlled — later withdrawing and bridging the proceeds off-chain. This was exploited on ixo mainnet
(ixo-5) on 2026-06-20. The attack required no victim keys, signatures, or system compromise — any account
holding a balance in a token a bond could use was at risk. This was fixed in v8.0.0, delivered via the on-
chain v8 software-upgrade. The x/bonds module is disabled: every bonds message is rejected on all routes
(top-level, authz, CosmWasm, and ICA), and the bonds batch EndBlocker is a no-op so no further reserve
movements can occur. All node operators and validators must upgrade to v8.0.0. The flaw is in chain state-
machine logic and can only be remediated by running the patched binary. There is no application-level
workaround. The vulnerability is in consensus logic; remediation requires the network to run the patched
(v8.0.0) binary. The bonds module remains disabled in v8.0.0 and will only be re-enabled in a future
release once the signer-authorization model has been corrected. (CVE-2026-61604)

Solution

Update the github.com/ixofoundation/ixo-blockchain/v8 library and its related packages to version 8.0.0 or later.

See Also

https://github.com/advisories/GHSA-w3rp-4cm2-4wgc

Plugin Details

Severity: Critical

ID: 448344

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 9/25/2026

Updated: 9/25/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.61

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.2

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2026-61604

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9.3

Threat Score: 8

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/24/2026

Vulnerability Publication Date: 9/24/2026

Reference Information

CVE: CVE-2026-61604