{"id":"GHSA-3j63-5h8p-gf7c","summary":"x402 SDK vulnerable in outdated versions in resource servers for builders","details":"### Impact\nThere is a security vulnerability in outdated versions of the x402 SDK. This does not directly affect users' keys, smart contracts, or funds.\n\nThis primarily impacts builders working on resource servers.\n\n### Patches\nPlease update to the following package versions:\n* x402 \u003e= 0.5.2\n* x402-next \u003e= 0.5.2\n* x402-express \u003e= 0.5.2\n* x402-hono \u003e= 0.5.2","modified":"2025-08-20T20:51:55Z","published":"2025-08-20T20:51:55Z","database_specific":{"nvd_published_at":null,"cwe_ids":[],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-08-20T20:51:55Z"},"references":[{"type":"WEB","url":"https://github.com/coinbase/x402/security/advisories/GHSA-3j63-5h8p-gf7c"},{"type":"PACKAGE","url":"https://github.com/coinbase/x402"}],"affected":[{"package":{"name":"x402","ecosystem":"npm","purl":"pkg:npm/x402"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.5.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-3j63-5h8p-gf7c/GHSA-3j63-5h8p-gf7c.json"}},{"package":{"name":"x402-next","ecosystem":"npm","purl":"pkg:npm/x402-next"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.5.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-3j63-5h8p-gf7c/GHSA-3j63-5h8p-gf7c.json"}},{"package":{"name":"x402-express","ecosystem":"npm","purl":"pkg:npm/x402-express"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.5.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-3j63-5h8p-gf7c/GHSA-3j63-5h8p-gf7c.json"}},{"package":{"name":"x402-hono","ecosystem":"npm","purl":"pkg:npm/x402-hono"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.5.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-3j63-5h8p-gf7c/GHSA-3j63-5h8p-gf7c.json"}}],"schema_version":"1.9.0"}