{"id":"GHSA-8x4m-qw58-3pcx","aliases":[],"url":"https://o3.security/vulnerability/GHSA-8x4m-qw58-3pcx","summary":"mppx has multiple payment bypass and griefing vulnerabilities","details":"### Impact\n\nMultiple vulnerabilities were discovered in `tempo/charge` and `tempo/session` which allowed for undesirable behaviors, including:\n- Replaying `tempo/charge` transaction hashes across push/pull modes, across charge/session endpoints, and via concurrent requests\n- Performing free `tempo/charge` requests due to missing transfer log verification in pull-mode\n- Replaying `tempo/charge` credentials across routes via cross-route scope confusion (`memo`/`splits` not included in scope binding)\n- Manipulating the fee payer of a `tempo/charge` handler into paying for requests (missing sender signature before co-signing)\n- Bypassing `tempo/session` voucher signature verification\n- Piggybacking off existing `tempo/session` channels via settle voucher reuse and weak channel ID binding\n- Performing free `tempo/session` requests by exploiting channel reopen without on-chain settled state\n- Accepting deductions on finalized `tempo/session` channels\n- Bypassing payment on free routes via method-mismatch fallback\n- Griefing `tempo/session` channels via force-close detection bypass (`closeRequestedAt` not persisted)\n\n### Patches\n\nFixed in 0.4.8.\n\n### Workarounds\n\nThere are no workarounds available for these vulnerabilities.","published":"2026-03-29T15:15:36Z","modified":"2026-03-29T15:35:52.545768Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"mppx","fixedVersion":"0.4.8"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/wevm/mppx/security/advisories/GHSA-8x4m-qw58-3pcx"},{"type":"PACKAGE","url":"https://github.com/wevm/mppx"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-03-29T15:35:52.545768Z"}}