Authentication Bypass in ZenHive mpp Affects Token Transactions
CVE-2026-73136
What is CVE-2026-73136?
The vulnerability in ZenHive mpp allows an unauthenticated third party to exploit the authentication process through capture-replay attacks. By replaying previously settled TIP-20 transfer transactions, attackers can obtain paid resources intended for others. This flaw arises from a failure to properly bind a specific challenge to the static memo used within method_config. As a result, attackers can leverage public transfers and request new challenges while presenting transaction hashes from legitimate transfers. This exposes systems to misuse and unauthorized access, highlighting the need for immediate patching and security best practices.
Affected Version(s)
mpp 0.6.1 < 0.6.4
mpp 542a525563c2fcedd670b593437deca81c6797a4 < 2207d7f456ae14c1d3fcacc6f635bf4f8cee1a34
