{"id":"GHSA-3j63-5h8p-gf7c","aliases":[],"url":"https://o3.security/vulnerability/GHSA-3j63-5h8p-gf7c","summary":"x402 SDK vulnerable in outdated versions in resource servers for builders","details":"### Impact\nThere is a security vulnerability in outdated versions of the x402 SDK. This does not directly affect users' keys, smart contracts, or funds.\n\nThis primarily impacts builders working on resource servers.\n\n### Patches\nPlease update to the following package versions:\n* x402 >= 0.5.2\n* x402-next >= 0.5.2\n* x402-express >= 0.5.2\n* x402-hono >= 0.5.2","published":"2025-08-20T20:51:55Z","modified":"2025-08-20T20:51:55Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"x402","fixedVersion":"0.5.2"},{"ecosystem":"npm","name":"x402-next","fixedVersion":"0.5.2"},{"ecosystem":"npm","name":"x402-express","fixedVersion":"0.5.2"},{"ecosystem":"npm","name":"x402-hono","fixedVersion":"0.5.2"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/coinbase/x402/security/advisories/GHSA-3j63-5h8p-gf7c"},{"type":"PACKAGE","url":"https://github.com/coinbase/x402"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-08-20T20:51:55Z"}}