mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the stripe/charge payment method did not check Stripe's Idempotent-Replayed response header when creating Paymen…
High CVSS 8.1
Summary
mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the stripe/charge payment method did not check Stripe's Idempotent-Replayed response header when creating PaymentIntents. An attacker could replay a valid credential containing the same spt token against a new challenge, and the server would accept the replayed Stripe PaymentIntent as a new successful payment without actually charging the customer again. This allowed an attacker to pay once and consume unlimi…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/wevm/mppx/commit/b2b1a0b60506fc71aa80b8a025084949dca1a994 Patch
- https://github.com/wevm/mppx/releases/tag/mppx@0.4.11 Release Notes
- https://github.com/wevm/mppx/security/advisories/GHSA-8mhj-rffc-rcvw Patch
Timeline
- nvd_ingest NVD