Description
A security vulnerability exists in outdated versions of the x402 SDK.
This vulnerability does not affect users’ private keys, smart contracts, or funds.
The issue impacts resource servers accepting payments on Solana when the facilitator is running a vulnerable version of the x402 SDK.
Recommendation
Update the @x402/svm package to the latest compatible version. Followings are version details:
- Affected version(s): < 2.6.0
- Patched version(s): 2.6.0
References
Could your website be exposed too?
SmartScanner can check your website for x402 SDK Security Advisory and gives you actionable findings to investigate.
Start a free scanRelated Issues
- x402 SDK vulnerable in outdated versions in resource servers for builders - Vulnerability
- x402 SDK vulnerable in outdated versions in resource servers for builders - x402 - Vulnerability
- Improper Authorization in @sap-cloud-sdk/core - Vulnerability
- Sentry SDK Prototype Pollution gadget in JavaScript SDKs - Vulnerability


