Executive brief
ZenHive mpp is a library that manages micropayment channels, allowing clients to pay for resources. A validation flaw in the payment processing logic allows an attacker with an open payment channel to reuse a single paid voucher multiple times, obtaining unlimited resources without additional charges. This effectively provides free access to paid services to any authenticated channel holder.
Technical details
The vulnerability is an improper input validation flaw in MPP.Session.Actions.accept_voucher/3 (lib/mpp/session/actions.ex). When a voucher's cumulativeAmount matches the channel's already-accepted cumulative amount, the function incorrectly treats this as idempotent success and skips the spending validation via maybe_spend/2. Since the server issues a fresh challenge per request but the credential replay store keys only on challenge ID and payload, an attacker can replay the same signed voucher indefinitely across multiple requests. The vulnerability is reachable through all MPP transports (Plug, MCP, JSON-RPC, WebSocket) and affects any method built on MPP.Session.Method.
Affected products
- ZenHive mpp 0.14.0 to before 0.16.2
Timeline
- 2026-09-22: disclosed
- 2026: patched: Fixed in version 0.16.2