Improper Input Validation in ZenHive mpp Affects Remote Clients
CVE-2026-88255
6.3MEDIUM
What is CVE-2026-88255?
An issue in ZenHive's mpp allows an unauthenticated remote client to exploit improper validation of input, leading to the possibility of passing the Tempo duplicate-submission gate twice using a single signed transaction. This occurs due to the handling of transaction forms and reserve keys, which enables duplicate transactions to be accepted when the same transaction is submitted with different recovery id encodings. As a result, an attacker can create multiple valid Payment-Receipts from what should be a single on-chain payment, posing significant risks to transaction integrity.
Affected Version(s)
mpp 0.2.0 < 0.16.2
mpp f8904666061fbab695874856d8fcd02c471dfe1b
