Executive brief
mppx is a TypeScript library used for handling machine-to-machine payments. A security flaw in its Stripe payment integration allows an attacker to reuse a single successful payment credential multiple times. This could allow a malicious user to pay for a service once and then consume unlimited resources or services without being charged again, leading to significant financial loss for the provider.
Technical details
A credential replay vulnerability exists in the stripe/charge payment method of the mppx library. The root cause is an incorrect comparison (CWE-697) where the server fails to validate Stripe's 'Idempotent-Replayed' response header when creating PaymentIntents. An attacker with low privileges can capture a valid credential containing a specific 'spt' token and replay it against new challenges. Because the server does not detect that the Stripe PaymentIntent has already been processed, it treats the replayed request as a new successful payment without initiating a new charge. This issue is fixed in version 0.4.11 by implementing mandatory checks for the idempotency header.
Affected products
- wevm mppx < 0.4.11
Timeline
- 2026-03-26: patched: Version 0.4.11 released with fix
- 2026-03-31: disclosed: Security advisory published by GitHub and NVD