Stability pool receives users' NFTs during the call to lendingPool.finalizeLiquidation. However, there's no logic to handle the received NFTs in the stability Pool. This can result in NFTs becoming permanently trapped in the Stability Pool contract.
finalizeLiquidation
The transfer was made using transferFrom which doesn't check for NFT receiver interface implementation.
Permanent loss of NFT assets which can lead to protocol insolvency
Manual
Implement logic to handle NFTs
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.