Junglewise Threat Intelligence

Coinbase x402 SDK vulnerability in resource servers

Severity: info · CVSS 7.5 · Published 2025-08-20

Vendors: npm.

Executive brief

A security vulnerability exists in outdated versions of the x402 SDK, a toolkit used for building internet payment protocols. The issue primarily affects developers managing resource servers rather than end-user funds or smart contracts. While user keys remain secure, organizations using these libraries should update to ensure the integrity of their server infrastructure.

Technical details

A vulnerability exists in the x402 SDK and its associated middleware packages (x402-next, x402-express, and x402-hono) prior to version 0.5.2. The flaw specifically impacts resource servers used by builders in the x402 payment protocol ecosystem. While the advisory notes that user keys, smart contracts, and funds are not directly affected, the vulnerability resides within the server-side implementation of the SDK. Developers are advised to upgrade all x402-related NPM packages to version 0.5.2 or higher to mitigate the risk.

Affected products

  • Coinbase x402 SDK < 0.5.2
  • Coinbase x402-next < 0.5.2
  • Coinbase x402-express < 0.5.2
  • Coinbase x402-hono < 0.5.2

Timeline

  • 2025-08-20: advisory: GitHub Security Advisory published
  • 2025-08-20: patched: Version 0.5.2 released to address the issue

References