mppx is vulnerable to Authentication Bypass via Signature Replay
70
High Risk
Tempo proof signatures (EIP-712) were not bound to the challenge realm, allowing proofs/signatures to be potentially reused or validated in unintended contexts (cross-realm replay/misuse). The patch updates the proof message/typed-data schema and signature verification to include realm, and fixes credential challenge.opaque serialization to ensure verification inputs match the intended spec format.
You are affected if you are using a version that falls within the vulnerable range.
mppx is vulnerable to Authentication Bypass via Signature Replay in versions 0.5.0 - 0.6.4.
Upgrade the mppx library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant