{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ainsumermodelmppx-condition-gate/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:insumermodel:mppx-condition-gate:*:*:*:*:*:*:*:*","cpe:2.3:a:insumermodel:mppx-token-gate:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-104891"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@insumermodel/mppx-condition-gate (\u003c= 2.0.3)","@insumermodel/mppx-token-gate (\u003c= 1.0.3)"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","cve-2026-104891","supply-chain"],"_cs_type":"advisory","_cs_vendors":["Insumer"],"content_html":"\u003cp\u003eResearch has identified a critical authentication bypass vulnerability, tracked as CVE-2026-104891, within the @insumermodel/mppx-condition-gate and @insumermodel/mppx-token-gate npm packages. These packages are designed to provide free-access pathways to paid services if a cryptocurrency wallet meets specific on-chain conditions. The vulnerability exists because the packages extract a payer address from a client-supplied DID (Decentralized Identifier) found in the \u003ccode\u003ecredential.source\u003c/code\u003e field and query an external API to verify if that address satisfies the conditions.\u003c/p\u003e\n\u003cp\u003eCrucially, the packages fail to verify that the requestor actually controls the wallet address they have supplied. Because qualifying wallet addresses are public chain state, an attacker can simply input a public address that meets the criteria to receive a successful access receipt. The packages perform this verification without calling the wrapped payment verifier, thereby bypassing the mandatory payment flow. An in-process cache, which defaults to a 300-second TTL keyed on the wallet address, then serves this unauthorized grant to subsequent requests without further validation. All published versions (up to 2.0.3 for mppx-condition-gate and 1.0.3 for mppx-token-gate) are affected.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthorized users to access paid digital services without providing valid payment or proving control over a qualifying asset. By targeting the service-side implementation of the condition gate, attackers can effectively grant themselves free access to premium routes across any application utilizing these libraries. This represents a direct financial loss for service providers and potential mass abuse of protected digital assets.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate removal of the condition gate from all payment methods until upgraded versions are deployed to the environment.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade @insumermodel/mppx-condition-gate to a patched version beyond 2.0.3 and @insumermodel/mppx-token-gate to a version beyond 1.0.3 immediately upon availability.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not possible, disable the condition gate logic to force all requests through the standard paid payment path, ensuring that wallet control is verified via the wrapped payment verifier.\u003c/li\u003e\n\u003cli\u003eAudit application-level logs to identify repeated requests that leverage high-value wallet addresses as \u003ccode\u003ecredential.source\u003c/code\u003e inputs from disparate network origins, as this may indicate exploitation of the cache mechanism.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-08T04:47:47Z","date_published":"2026-10-08T04:47:47Z","id":"https://feed.craftedsignal.io/briefs/2026-10-mppx-gate-bypass/","summary":"The @insumermodel/mppx-condition-gate and @insumermodel/mppx-token-gate packages incorrectly trust a client-supplied wallet address, allowing attackers to bypass payment requirements by referencing any qualifying wallet address.","title":"Authentication Bypass in Insumer mppx Condition Gate Packages","url":"https://feed.craftedsignal.io/briefs/2026-10-mppx-gate-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:insumermodel:mppx-Condition-Gate:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}