CVE-2026-34210High· 8.1▾ Twilightmppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the stripe/charge payment method did not check Stripe's Idempotent-Replayed response header when creating PaymentIntents. An attacker could replay a v…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 24.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the stripe/charge payment method did not check Stripe's Idempotent-Replayed response header when creating PaymentIntents. An attacker could replay a valid credential containing the same spt token against a new challenge, and the server would accept the replayed Stripe PaymentIntent as a new successful payment without actually charging the customer again. This allowed an attacker to pay once and consume unlimited resources by replaying the credential. This issue has been patched in version 0.4.11.
mppx < 0.4.11Upgrade past the affected range:
mppx 0.4.11Connected by shared product, vendor, weakness, or advisory.
CVE-2026-34209High· 7.5mppx is a TypeScript interface for machine payments protocol
CVE-2026-63627Medium· 6.9mppx is a TypeScript interface for machine payments protocol
CVE-2026-63628Medium· 6.9mppx is a TypeScript interface for machine payments protocol
CVE-2026-79913Medium· 6.5Cloudreve is a self-hosted file management and sharing system
CVE-2026-93957Medium· 4.3A vulnerability has been found in olivier-ls PHP-FTS up to 1.1.3
CVE-2026-71855Medium· 5.9Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine