highVulnerability

GHSA-qr2g-p6q7-w82m

### Impact A security vulnerability exists in outdated versions of the x402 SDK. This vulnerability does not affect users' private keys, smart contracts, or funds. The issue impacts resource servers accepting payments on Solana when the facilitator is running a vulnerable version of the x402 SDK. ### Who Should Take Action Facilitators that process payments on Solana must upgrade the x402 SDK to the patched versions listed below. Clients are not required to upgrade. Resource servers are not required to upgrade unless they operate their own facilitator (self-facilitate). ### Patches Please update to the following package versions: * Npm: @x402/svm >= 2.6.0 * Pypi: x402 >= 2.3.0 * Go: x402 >= 2.5.0

Properties

ghsa_id
GHSA-qr2g-p6q7-w82m
summary
x402 SDK Security Advisory
severity
high
cve_id
GHSA-qr2g-p6q7-w82m
is_ghsa_only
true
ghsa_published
2026-03-07T02:37:47Z
source_url
https://github.com/advisories/GHSA-qr2g-p6q7-w82m
ghsa_updated
2026-03-07T02:37:48Z

Related Entities (4)

AFFECTS (3)

[Software]npm/@x402/svm
[Software]go/github.com/coinbase/x402/go
[Software]pip/x402

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph