VYPR

Mppx

by Wevm

npm: mppx

Source repositories

CVEs (4)

  • CVE-2026-34210HigMar 31, 2026
    risk 0.46cvss 8.1epss 0.01

    mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the stripe/charge payment method did not check Stripe's Idempotent-Replayed response header when creating PaymentIntents. An attacker could replay a valid credential containing the same spt…

  • CVE-2026-34209HigMar 31, 2026
    risk 0.42cvss 7.5epss 0.00

    mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the tempo/session cooperative close handler validated the close voucher amount using "<" instead of "<=" against the on-chain settled amount. An attacker could submit a close voucher exactly…

  • CVE-2026-63628MedSep 22, 2026
    risk 0.38cvss —epss 0.00

    mppx is a TypeScript interface for machine payments protocol. Prior to 0.8.2, the fee-payer cosigning path in src/tempo/internal/fee-payer.ts copied a client-supplied access_list from a 0x78 FeePayerEnvelope without validating its length or contents. Because EIP-2930 access-list…

  • CVE-2026-63627MedSep 22, 2026
    risk 0.38cvss —epss 0.00

    mppx is a TypeScript interface for machine payments protocol. Prior to 0.8.2, FeePayerPolicy in src/tempo/internal/fee-payer.ts used decodeFunctionData to validate fee-sponsored calldata but did not reject trailing bytes. A client could append nonzero padding that increased…