mppx is vulnerable to Replay Attacks
53
Medium Risk
Affected versions of this package do not validate the expiration of client challenges before generating credentials, which allows expired challenges to be accepted and processed. This behavior enables a replay attack scenario where an attacker can reuse a previously intercepted challenge (e.g., from a WWW-Authenticate header) beyond its intended validity window. Because the client proceeds with credential creation without enforcing freshness, the same challenge can be replayed multiple times to obtain valid credentials or trigger repeated payments.
You are affected if you are using a version that falls within the vulnerable range.
mppx is vulnerable to Replay Attacks in versions 0.0.1 - 0.6.14.
Upgrade the mppx library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant