mppx
npm4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting mppxpage 1 of 1
- CVE-2026-34209HIGHCVSS 7.5EG 7.5fixed in 0.4.112026-03-31
mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the tempo/session cooperative close handler validated the close voucher amount using "<" instead of "<=" against the on-chain settled amount. An attacke…
- CVE-2026-34210HIGHCVSS 8.1EG 8.1fixed in 0.4.112026-03-31
mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the stripe/charge payment method did not check Stripe's Idempotent-Replayed response header when creating PaymentIntents. An attacker could replay a val…
- CVE-2026-63627MEDIUMCVSS 6.9EG 6.9fixed in 0.8.22026-09-22
mppx is a TypeScript interface for machine payments protocol. Prior to 0.8.2, FeePayerPolicy in src/tempo/internal/fee-payer.ts used decodeFunctionData to validate fee-sponsored calldata but did not reject trailing bytes. A client could ap…
- CVE-2026-63628MEDIUMCVSS 6.9EG 6.9fixed in 0.8.22026-09-22
mppx is a TypeScript interface for machine payments protocol. Prior to 0.8.2, the fee-payer cosigning path in src/tempo/internal/fee-payer.ts copied a client-supplied access_list from a 0x78 FeePayerEnvelope without validating its length o…
Check whether mppx is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for mppx CVEs against the assets you own.
Book a Demo →