criticalVulnerability

GHSA-8x4m-qw58-3pcx

### Impact Multiple vulnerabilities were discovered in `tempo/charge` and `tempo/session` which allowed for undesirable behaviors, including: - Replaying `tempo/charge` transaction hashes across push/pull modes, across charge/session endpoints, and via concurrent requests - Performing free `tempo/charge` requests due to missing transfer log verification in pull-mode - Replaying `tempo/charge` credentials across routes via cross-route scope confusion (`memo`/`splits` not included in scope binding) - Manipulating the fee payer of a `tempo/charge` handler into paying for requests (missing sender signature before co-signing) - Bypassing `tempo/session` voucher signature verification - Piggybacking off existing `tempo/session` channels via settle voucher reuse and weak channel ID binding - Performing free `tempo/session` requests by exploiting channel reopen without on-chain settled state - Accepting deductions on finalized `tempo/session` channels - Bypassing payment on free routes via method-mismatch fallback - Griefing `tempo/session` channels via force-close detection bypass (`closeRequestedAt` not persisted) ### Patches Fixed in 0.4.8. ### Workarounds There are no workarounds available for these vulnerabilities.

Properties

ghsa_id
GHSA-8x4m-qw58-3pcx
severity
critical
summary
mppx has multiple payment bypass and griefing vulnerabilities
cve_id
GHSA-8x4m-qw58-3pcx
is_ghsa_only
true
ghsa_published
2026-03-29T15:15:36Z
source_url
https://github.com/advisories/GHSA-8x4m-qw58-3pcx
ghsa_updated
2026-03-29T15:15:37Z

Related Entities (5)

AFFECTS (1)

[Software]npm/mppx

HAS_WEAKNESS (3)

[Weakness]Insufficient Verification of Data Authenticity
[Weakness]Authentication Bypass Using an Alternate Path or Channel
[Weakness]Authentication Bypass by Capture-replay

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-8x4m-qw58-3pcx — Ninja Signal Threat Intelligence | Ninja Signal