目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-104891— mppx-condition-gate 自声明钱包未验证控制权限漏洞

一分钟漏洞结论

影响对象
douglasborthwick-crypto mppx-condition-gate
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

为 MPPX 支付方式提供了条件性的免费访问包装器。在 版本低于 3.0.0 以及 版本低于 1.0.4 的旧版本中,这些包会从客户端提供的凭证 中读取一个钱包地址,检查该公共地址是否满足链上配置的条件的结果,返回一个成功的免费访问凭证,而无需调用被包装的支付验证器,也无需证明调用者实际上控制着该钱包。 未经验证的攻击者可以任意指定一个符合条件的钱包地址,从而获得本应需要付费才能访问的内容;此外,缓存的授权凭证可以在配置的缓存有效期内被重复使用。 修复后的版本仅在确认支付者已建立钱包控制权的前提下,才允许免费访问授

CVSS 7.5 · High
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-104891 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
mppx-condition-gate: Free-access path grants on a self-declared wallet without proving control
来源: CVE Program / CVE List V5
Vulnerability Description
mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4, the packages read a wallet address from the client-supplied credential.source, checked whether that public address met configured on-chain conditions, and returned a successful free-access receipt without invoking the wrapped payment verifier or proving that the caller controlled the wallet. An unauthenticated attacker could name any qualifying wallet and obtain content that should require payment, and cached grants could be reused for the configured cache lifetime. The corrected packages prevent free-access authorization unless payer control has been established. These issues are fixed in @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
使用欺骗进行的认证绕过
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
douglasborthwick-crypto mppx-condition-gate < b1d9935a57ba6d32da49eead1bfb459ad0cd55ab -
@insumermodel mppx-condition-gate < 3.0.0 -
@insumermodel mppx-token-gate < 1.0.4 -

二、漏洞 CVE-2026-104891 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-104891 的情报信息

请登录查看更多情报信息。

CVE-2026-104891 其他参考 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-104891

暂无评论


发表评论