TypeScript Interface Vulnerability in mppx Payment Method by wevm
CVE-2026-34210

6MEDIUM

Key Information:

Vendor

Wevm

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-34210?

The mppx TypeScript interface for machine payments protocol had a vulnerability where the stripe/charge payment method failed to validate the Stripe's Idempotent-Replayed response header before creating PaymentIntents. This weakness allowed attackers to exploit a valid credential with the same spt token, enabling them to replay the credential against new challenges. As a result, malicious actors could mimic successful payments without additional charges to the customer, leading to potential resource misuse. The issue has been addressed in version 0.4.11, where necessary validation measures were implemented.

Affected Version(s)

mppx < 0.4.11

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.