mppx is vulnerable to Replay Attacks
53
Medium Risk
An improper authorization issue in wevm mppx allowed payment credentials to be reused across different API routes because challenges were not bound to a route-specific scope and verifyCredential() did not enforce scope matching, enabling cross-route replay of valid credentials and unauthorized access to protected endpoints with equivalent pricing parameters.
You are affected if you are using a version that falls within the vulnerable range.
mppx is vulnerable to Replay Attacks in versions 0.0.1 - 0.6.1.
Upgrade the mppx library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant