CVE-2026-104891
Received Received - Intake

Unauthenticated Free-Access Bypass in mppx-condition-gate

Vulnerability report for CVE-2026-104891, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4, the packages read a wallet address from the client-supplied credential.source, checked whether that public address met configured on-chain conditions, and returned a successful free-access receipt without invoking the wrapped payment verifier or proving that the caller controlled the wallet. An unauthenticated attacker could name any qualifying wallet and obtain content that should require payment, and cached grants could be reused for the configured cache lifetime. The corrected packages prevent free-access authorization unless payer control has been established. These issues are fixed in @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
douglasborthwick-crypto mppx-condition-gate < b1d9935a57ba6d32da49eead1bfb459ad0cd55ab
@insumermodel mppx-condition-gate < 3.0.0
@insumermodel mppx-token-gate < 1.0.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-290 This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects packages designed to grant free access to wallets meeting on-chain conditions without proper payment verification. The issue occurs because the packages read a wallet address from client-supplied data and return free access without validating that the caller controls the wallet. An attacker can exploit this by naming any qualifying wallet address, bypassing payment requirements. The vulnerability was fixed by requiring proof of wallet control before granting free access.

Detection Guidance

To detect this vulnerability, check if your system uses affected versions of @insumermodel/mppx-condition-gate (<=2.0.3) or @insumermodel/mppx-token-gate (<=1.0.3). Inspect package.json files for these dependencies. Look for unauthorized free access grants in logs where credential.source is used without validation.

Impact Analysis

An unauthenticated attacker could obtain paid content for free by exploiting this vulnerability. They could name any qualifying wallet address and receive a free-access receipt without making a payment. Additionally, cached grants could be reused for up to 300 seconds, allowing repeated unauthorized access. This compromises the confidentiality of protected resources and undermines the intended payment model.

Compliance Impact

This vulnerability allows unauthorized free access to paid content by bypassing payment verification, which could lead to unauthorized data exposure. This may violate compliance requirements under GDPR (data protection) and HIPAA (healthcare data privacy) by exposing protected resources without proper authorization.

Mitigation Strategies

Upgrade to @insumermodel/mppx-condition-gate 3.0.0+ or remove the condition gate temporarily. For mppx-token-gate, upgrade to 1.0.4 or higher. Ensure no free access is granted without proof of wallet control via provenPayer resolver.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104891. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart