EXECUTIVE SUMMARY:
A high-severity vulnerability affecting @insumermodel/mppx-condition-gate versions <= 2.0.3 affecting @insumermodel/mppx-token-gate versions <= 1.0.3, assigned CVE-2026-104891 with a CVSS score of 7.5, affects every published version of the @insumermodel/mppx-condition-gate and @insumermodel/mppx-token-gate packages, which grant free access to a route that should have been paid for by exploiting the lack of control validation over the client-supplied DID in the payment credential, allowing an attacker to name any qualifying address and obtain free access without ever calling the wrapped payment verifier; this is a defect in these wrapper packages, not in the attestation they consume, which answers one question — does this wallet satisfy these conditions — but fails to bind that address to the caller, who must validate the relationship to the credential payload according to mppx type definitions; the flaw type is CWE-290 and CWE-863, with an attack vector of network access and a business impact including unauthorized access and potential financial loss.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A high-severity vulnerability affecting @insumermodel/mppx-condition-gate versions <= 2.0.3 affecting @insumermodel/mppx-token-gate versions <= 1.0.3, assigned CVE-2026-104891 with a CVSS score of 7.5, affects every published version of the @insumermodel/mppx-condition-gate and @insumermodel/mppx-token-gate packages, which grant free access to a route that should have been paid for by exploiting the lack of control validation over the client-supplied DID in the payment credential, allowing an attacker to name any qualifying address and obtain free access without ever calling the wrapped payment verifier; this is a defect in these wrapper packages, not in the attestation they consume, which answers one question — does this wallet satisfy these conditions — but fails to bind that address to the caller, who must validate the relationship to the credential payload according to mppx type definitions; the flaw type is CWE-290 and CWE-863, with an attack vector of network access and a business impact including unauthorized access and potential financial loss.[emaillocker id="1283"]
RECOMMENDATIONS:
REFERENCES:
The following reports contain further technical details:
https://github.com/advisories/GHSA-jg6q-3qfh-r9f8