Description
mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4, the packages read a wallet address from the client-supplied credential.source, checked whether that public address met configured on-chain conditions, and returned a successful free-access receipt without invoking the wrapped payment verifier or proving that the caller controlled the wallet. An unauthenticated attacker could name any qualifying wallet and obtain content that should require payment, and cached grants could be reused for the configured cache lifetime. The corrected packages prevent free-access authorization unless payer control has been established. These issues are fixed in @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4.
Published: 2026-10-05
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Unauthorized access to paid content
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the mppx-condition-gate and mppx-token-gate libraries, where a claim of free access is granted based solely on a wallet address supplied by the client, without verifying that the claimant controls that wallet. An attacker can therefore supply any address that satisfies on‑chain conditions, receive a free‑access receipt, and download content that should require payment. This results in an unauthorized disclosure of paid content, compromising confidentiality. The weakness corresponds to authentication bypass (CWE‑290) and missing authorization (CWE‑863).

Affected Systems

Affected vendors include Insumermodel’s mppx-condition-gate and mppx-token-gate, and the related douglasborthwick‑crypto project. Versions before 3.0.0 of mppx-condition-gate and before 1.0.4 of mppx-token-gate are vulnerable. No other versions were identified by the CNA as impacted.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. EPSS is unavailable but the vulnerability is not listed in the CISA KEV catalogue, suggesting it has not yet been widely exploited. An unauthenticated attacker can send a request to the payment wrapper with a chosen wallet address that meets the configured on‑chain conditions, obtain a valid free‑access receipt, and access protected content. Cached grants may be reused for the cache lifetime, allowing repeated abuse without repeated credential submission.

Generated by OpenCVE AI on October 5, 2026 at 17:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to mppx‑condition‑gate version 3.0.0 or later, which requires valid wallet control before issuing free‑access receipts.
  • Update to mppx‑token‑gate version 1.0.4 or later, which enforces the same control verification.
  • Review and modify the integration to ensure that any wallet control proof (e.g., signed message) is verified before granting free access, and consider reducing the cache lifetime if cached grants persist longer than necessary.

Generated by OpenCVE AI on October 5, 2026 at 17:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4, the packages read a wallet address from the client-supplied credential.source, checked whether that public address met configured on-chain conditions, and returned a successful free-access receipt without invoking the wrapped payment verifier or proving that the caller controlled the wallet. An unauthenticated attacker could name any qualifying wallet and obtain content that should require payment, and cached grants could be reused for the configured cache lifetime. The corrected packages prevent free-access authorization unless payer control has been established. These issues are fixed in @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4.
Title mppx-condition-gate: Free-access path grants on a self-declared wallet without proving control
Weaknesses CWE-290
CWE-863
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T15:55:28.731Z

Reserved: 2026-10-02T14:59:11.775Z

Link: CVE-2026-104891

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T16:17:06.447

Modified: 2026-10-05T16:17:06.447

Link: CVE-2026-104891

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T17:30:11Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing

  • CWE-863

    Incorrect Authorization