mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4, the packages read a wallet address from the client-supplied credential.source, checked whether that public address met configured on-chain conditions, and returned a successful free-access receipt without invoking the wrapped payment verifier or proving that the caller controlled the wallet. An unauthenticated attacker could name any qualifying wallet and obtain content that should require payment, and cached grants could be reused for the configured cache lifetime. The corrected packages prevent free-access authorization unless payer control has been established. These issues are fixed in @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4.

Project Subscriptions

Vendors Products
Douglasborthwick-crypto Subscribe
Mppx-condition-gate Subscribe
Insumermodel Subscribe
Mppx-condition-gate Subscribe
Mppx-token-gate Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 06 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Douglasborthwick-crypto
Douglasborthwick-crypto mppx-condition-gate
Insumermodel
Insumermodel mppx-condition-gate
Insumermodel mppx-token-gate
Vendors & Products Douglasborthwick-crypto
Douglasborthwick-crypto mppx-condition-gate
Insumermodel
Insumermodel mppx-condition-gate
Insumermodel mppx-token-gate

Mon, 05 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4, the packages read a wallet address from the client-supplied credential.source, checked whether that public address met configured on-chain conditions, and returned a successful free-access receipt without invoking the wrapped payment verifier or proving that the caller controlled the wallet. An unauthenticated attacker could name any qualifying wallet and obtain content that should require payment, and cached grants could be reused for the configured cache lifetime. The corrected packages prevent free-access authorization unless payer control has been established. These issues are fixed in @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4.
Title mppx-condition-gate: Free-access path grants on a self-declared wallet without proving control
Weaknesses CWE-290
CWE-863
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T19:53:16.624Z

Reserved: 2026-10-02T14:59:11.775Z

Link: CVE-2026-104891

cve-icon Vulnrichment

Updated: 2026-10-05T19:53:12.496Z

cve-icon NVD

Status : Deferred

Published: 2026-10-05T16:17:06.447

Modified: 2026-10-06T16:08:43.180

Link: CVE-2026-104891

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:57:28Z

Weaknesses