Impact
The vulnerability resides in the mppx-condition-gate and mppx-token-gate libraries, where a claim of free access is granted based solely on a wallet address supplied by the client, without verifying that the claimant controls that wallet. An attacker can therefore supply any address that satisfies on‑chain conditions, receive a free‑access receipt, and download content that should require payment. This results in an unauthorized disclosure of paid content, compromising confidentiality. The weakness corresponds to authentication bypass (CWE‑290) and missing authorization (CWE‑863).
Affected Systems
Affected vendors include Insumermodel’s mppx-condition-gate and mppx-token-gate, and the related douglasborthwick‑crypto project. Versions before 3.0.0 of mppx-condition-gate and before 1.0.4 of mppx-token-gate are vulnerable. No other versions were identified by the CNA as impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. EPSS is unavailable but the vulnerability is not listed in the CISA KEV catalogue, suggesting it has not yet been widely exploited. An unauthenticated attacker can send a request to the payment wrapper with a chosen wallet address that meets the configured on‑chain conditions, obtain a valid free‑access receipt, and access protected content. Cached grants may be reused for the cache lifetime, allowing repeated abuse without repeated credential submission.
OpenCVE Enrichment