pypi package report

Is x402 safe?

1 known vulnerability, worst severity HIGH.

// reach

22 direct dependencies

11 carry known advisories, worst CRITICAL

6 packages depend on it

an advisory here reaches each of them

Create a free accountfor every dependency path, dependent and what to upgrade
// ai model usage

No published models are known to use this package.


cvss
0.0
high

severity band, no base score published

epss
not scored

chance of exploitation in 30 days

xyz score
0.0
medium

CyberXYZ composite out of 10

fig. 01 — GHSA-qr2g-p6q7-w82m, the advisory selected below

// 1 advisories

GHSA-qr2g-p6q7-w82m

HIGH
// impact

A security vulnerability exists in outdated versions of the x402 SDK.

This vulnerability does not affect users' private keys, smart contracts, or funds.

The issue impacts resource servers accepting payments on Solana when the facilitator is running a vulnerable version of the x402 SDK.

// who should take action

Facilitators that process payments on Solana must upgrade the x402 SDK to the patched versions listed below.

Clients are not required to upgrade.

Resource servers are not required to upgrade unless they operate their own facilitator (self-facilitate).

// patches

Please update to the following package versions:

  • Npm: @x402/svm >= 2.6.0
  • Pypi: x402 >= 2.3.0
  • Go: x402 >= 2.5.0

Checked 2026-09-28 at 19:51 UTC. The most recent advisory here was published 2026-03-07. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.