Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104891— mppx-condition-gate: Free-access path grants on a self-declared wallet without proving control

Quick assessment

Affected
douglasborthwick-crypto mppx-condition-gate
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

为 MPPX 支付方式提供了条件性的免费访问包装器。在 版本低于 3.0.0 以及 版本低于 1.0.4 的旧版本中,这些包会从客户端提供的凭证 中读取一个钱包地址,检查该公共地址是否满足链上配置的条件的结果,返回一个成功的免费访问凭证,而无需调用被包装的支付验证器,也无需证明调用者实际上控制着该钱包。 未经验证的攻击者可以任意指定一个符合条件的钱包地址,从而获得本应需要付费才能访问的内容;此外,缓存的授权凭证可以在配置的缓存有效期内被重复使用。 修复后的版本仅在确认支付者已建立钱包控制权的前提下,才允许免费访问授

CVSS 7.5 · High

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 3

VendorProduct Version RangeStatus
@insumermodel mppx-condition-gate < 3.0.0 affected
@insumermodel mppx-token-gate < 1.0.4 affected
douglasborthwick-crypto mppx-condition-gate < b1d9935a57ba6d32da49eead1bfb459ad0cd55ab affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104891

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
mppx-condition-gate: Free-access path grants on a self-declared wallet without proving control
Source: CVE Program / CVE List V5
Vulnerability Description
mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4, the packages read a wallet address from the client-supplied credential.source, checked whether that public address met configured on-chain conditions, and returned a successful free-access receipt without invoking the wrapped payment verifier or proving that the caller controlled the wallet. An unauthenticated attacker could name any qualifying wallet and obtain content that should require payment, and cached grants could be reused for the configured cache lifetime. The corrected packages prevent free-access authorization unless payer control has been established. These issues are fixed in @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用欺骗进行的认证绕过
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
douglasborthwick-crypto mppx-condition-gate < b1d9935a57ba6d32da49eead1bfb459ad0cd55ab -
@insumermodel mppx-condition-gate < 3.0.0 -
@insumermodel mppx-token-gate < 1.0.4 -

II. Public POCs for CVE-2026-104891

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104891

请登录查看更多情报信息。

Other References for CVE-2026-104891 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-104891

No comments yet


Leave a comment