PatchSiren cyber security CVE debrief
CVE-2026-104891 insumermodel CVE debrief
CVE-2026-104891: The mppx-condition-gate packages do not validate the relationship between the credential source and the payload, allowing an attacker to obtain free access to a route that should have been paid for by naming any qualifying address in the credential source. This vulnerability affects the npm packages @insumermodel/mppx-condition-gate and @insumermodel/mppx-token-gate. Defenders should assess exposure and prioritize verification and remediation. The vulnerability is caused by the free-access path reading the payer address from credential.source, a client-supplied DID, and asking InsumerAPI whether that address satisfies the configured conditions without establishing
- Vendor
- insumermodel
- Product
- mppx-condition-gate
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for the npm packages @insumermodel/mppx-condition-gate and @insumermodel/mppx-token-gate should assess exposure and prioritize verification and remediation. Defenders must verify the affected packages are not used in environments where free access could be exploited. Exposure could allow unauthorized access to paid routes. Remediation priority is high for environments using the affected versions. Further verification is needed to
Why it matters
CVE-2026-104891 allows free access to paid routes without proving control of the wallet, affecting the npm packages @insumermodel/mppx-condition-gate and @insumermodel/mppx-token-gate.
- Defenders must verify the affected packages are not used in environments where free access could be exploited.
- Exposure could allow unauthorized access to paid routes.
- Remediation priority is high for environments using the affected versions.
- Further verification is needed to determine the full scope of affected systems and potential exploitation.
Technical summary
The mppx-condition-gate packages do not validate the relationship between the credential source and the payload, allowing an attacker to obtain free access to a route that should have been paid for by naming any qualifying address in the credential source. This vulnerability affects the npm packages @insumermodel/mppx-condition-gate and @insumermodel/mppx-token-gate. The free-access path reads the payer address from credential.source, a client-supplied DID, and asks InsumerAPI whether that address satisfies the configured conditions without establishing control. An in-process cache then re-serves the grant without re-evaluating.
Defensive priority
Defenders should prioritize verifying the affected packages @insumermodel/mppx-condition-gate and @insumermodel/mppx-token-gate, and assess exposure in their environments.
Recommended defensive actions
- Verify the affected packages @insumermodel/mppx-condition-gate and @insumermodel/mppx-token-gate are not used in environments where free access could be exploited.
- Assess exposure by checking if the affected versions are in use.
- Update to the fixed versions 3.0.0 for @insumermodel/mppx-condition-gate and 1.0.4 for @insumermodel/mppx-token-gate.
- Monitor for potential exploitation attempts using the in-process cache.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The source corpus provides details on the vulnerability in the mppx-condition-gate packages, including the impact, affected versions 3.0.0 and 1.0.4 for @insumermodel/mppx-condition-gate and @insumermodel/mppx-token-gate, and fixed versions. The vulnerability allows free access to paid routes without proving control of the wallet. Defenders must verify the affected packages are not used in environments where free access could be exploited. Exposure could allow unauthorized access to paid routes. Remediation priority is high for The m
Sources and references
Verified primary and authoritative sources
-
CVE-2026-104891 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-104891
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-104891 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104891
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
mppx-condition-gate: Free-access path grants on a self-declared wallet without proving control
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-jg6q-3qfh-r9f8.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/douglasborthwick-crypto/mppx-condition-gate/security/advisories/GHSA-jg6q-3qfh-r9f8
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/insumerapi/mppx-condition-gate/security/advisories/GHSA-jg6q-3qfh-r9f8
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/insumerapi/mppx-condition-gate/commit/b1d9935a57ba6d32da49eead1bfb459ad0cd55ab
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/insumerapi/mppx-condition-gate/commit/ec43a2fcd443a0fa102b6d4203abed2b785bd954
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/douglasborthwick-crypto/mppx-condition-gate
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.