Junglewise Threat Intelligence

CVE-2026-34210: wevm mppx credential replay in stripe/charge payment method

CVE-2026-34210 · Severity: high · CVSS 8.1 · Published 2026-03-31

Technologies: Wevm Mppx. Vendors: Wevm.

Executive brief

mppx is a TypeScript library used for handling machine-to-machine payments. A security flaw in its Stripe payment integration allows an attacker to reuse a single successful payment credential multiple times. This could allow a malicious user to pay for a service once and then consume unlimited resources or services without being charged again, leading to significant financial loss for the provider.

Technical details

A credential replay vulnerability exists in the stripe/charge payment method of the mppx library. The root cause is an incorrect comparison (CWE-697) where the server fails to validate Stripe's 'Idempotent-Replayed' response header when creating PaymentIntents. An attacker with low privileges can capture a valid credential containing a specific 'spt' token and replay it against new challenges. Because the server does not detect that the Stripe PaymentIntent has already been processed, it treats the replayed request as a new successful payment without initiating a new charge. This issue is fixed in version 0.4.11 by implementing mandatory checks for the idempotency header.

Affected products

  • wevm mppx < 0.4.11

Timeline

  • 2026-03-26: patched: Version 0.4.11 released with fix
  • 2026-03-31: disclosed: Security advisory published by GitHub and NVD

References

Related threats