PT-2026-78535 · Zenhive · Zenhive Mpp
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ZenHive mpp versions 0.3.0 through 0.6.2
Description
An authentication bypass exists that allows an unauthenticated remote client to obtain paid resources by resubmitting a settled on-chain transfer. The
MPP.Methods.EVM.verify/2 function accepts a transaction-hash credential and matches a transfer based solely on the token, recipient, and amount for ERC-20 tokens, or the recipient and value for native tokens. Because the proof is not bound to the challenge being verified or to a record of prior use, and the MPP.Plug deduplication store keys are based on challenge.id (which is regenerated for every 402 response), a single historical transfer matching the charge can satisfy multiple subsequent charges. This allows an attacker to use transfers found on a public block explorer to bypass payment requirements on static-price routes.Recommendations
Update ZenHive mpp to version 0.6.3 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zenhive Mpp