The stale nft price can be used for calculating collateral value.
LendingPool.sol#getNFTPrice() function is as follows.
As we can see above, there is no stale check for oracle price. So dirty price can be used for calculating collateral vaue.
This wrong price will cause protocol's loss when real price is decreased.
Manual review
Add stale check to LendingPool.sol#getNFTPrice().
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.