<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Insumer - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/insumer/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 08 Oct 2026 04:47:47 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/insumer/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in Insumer mppx Condition Gate Packages</title><link>https://feed.craftedsignal.io/briefs/2026-10-mppx-gate-bypass/</link><pubDate>Thu, 08 Oct 2026 04:47:47 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-mppx-gate-bypass/</guid><description>The @insumermodel/mppx-condition-gate and @insumermodel/mppx-token-gate packages incorrectly trust a client-supplied wallet address, allowing attackers to bypass payment requirements by referencing any qualifying wallet address.</description><content:encoded><![CDATA[<p>Research has identified a critical authentication bypass vulnerability, tracked as CVE-2026-104891, within the @insumermodel/mppx-condition-gate and @insumermodel/mppx-token-gate npm packages. These packages are designed to provide free-access pathways to paid services if a cryptocurrency wallet meets specific on-chain conditions. The vulnerability exists because the packages extract a payer address from a client-supplied DID (Decentralized Identifier) found in the <code>credential.source</code> field and query an external API to verify if that address satisfies the conditions.</p>
<p>Crucially, the packages fail to verify that the requestor actually controls the wallet address they have supplied. Because qualifying wallet addresses are public chain state, an attacker can simply input a public address that meets the criteria to receive a successful access receipt. The packages perform this verification without calling the wrapped payment verifier, thereby bypassing the mandatory payment flow. An in-process cache, which defaults to a 300-second TTL keyed on the wallet address, then serves this unauthorized grant to subsequent requests without further validation. All published versions (up to 2.0.3 for mppx-condition-gate and 1.0.3 for mppx-token-gate) are affected.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability allows unauthorized users to access paid digital services without providing valid payment or proving control over a qualifying asset. By targeting the service-side implementation of the condition gate, attackers can effectively grant themselves free access to premium routes across any application utilizing these libraries. This represents a direct financial loss for service providers and potential mass abuse of protected digital assets.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the immediate removal of the condition gate from all payment methods until upgraded versions are deployed to the environment.</p>
<ul>
<li>Upgrade @insumermodel/mppx-condition-gate to a patched version beyond 2.0.3 and @insumermodel/mppx-token-gate to a version beyond 1.0.3 immediately upon availability.</li>
<li>If immediate patching is not possible, disable the condition gate logic to force all requests through the standard paid payment path, ensuring that wallet control is verified via the wrapped payment verifier.</li>
<li>Audit application-level logs to identify repeated requests that leverage high-value wallet addresses as <code>credential.source</code> inputs from disparate network origins, as this may indicate exploitation of the cache mechanism.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>authentication-bypass</category><category>cve-2026-104891</category><category>supply-chain</category></item></channel></rss>