PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-104891 insumermodel CVE debrief

CVE-2026-104891: The mppx-condition-gate packages do not validate the relationship between the credential source and the payload, allowing an attacker to obtain free access to a route that should have been paid for by naming any qualifying address in the credential source. This vulnerability affects the npm packages @insumermodel/mppx-condition-gate and @insumermodel/mppx-token-gate. Defenders should assess exposure and prioritize verification and remediation. The vulnerability is caused by the free-access path reading the payer address from credential.source, a client-supplied DID, and asking InsumerAPI whether that address satisfies the configured conditions without establishing

Vendor
insumermodel
Product
mppx-condition-gate
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for the npm packages @insumermodel/mppx-condition-gate and @insumermodel/mppx-token-gate should assess exposure and prioritize verification and remediation. Defenders must verify the affected packages are not used in environments where free access could be exploited. Exposure could allow unauthorized access to paid routes. Remediation priority is high for environments using the affected versions. Further verification is needed to

Why it matters

CVE-2026-104891 allows free access to paid routes without proving control of the wallet, affecting the npm packages @insumermodel/mppx-condition-gate and @insumermodel/mppx-token-gate.

  • Defenders must verify the affected packages are not used in environments where free access could be exploited.
  • Exposure could allow unauthorized access to paid routes.
  • Remediation priority is high for environments using the affected versions.
  • Further verification is needed to determine the full scope of affected systems and potential exploitation.

Technical summary

The mppx-condition-gate packages do not validate the relationship between the credential source and the payload, allowing an attacker to obtain free access to a route that should have been paid for by naming any qualifying address in the credential source. This vulnerability affects the npm packages @insumermodel/mppx-condition-gate and @insumermodel/mppx-token-gate. The free-access path reads the payer address from credential.source, a client-supplied DID, and asks InsumerAPI whether that address satisfies the configured conditions without establishing control. An in-process cache then re-serves the grant without re-evaluating.

Defensive priority

Defenders should prioritize verifying the affected packages @insumermodel/mppx-condition-gate and @insumermodel/mppx-token-gate, and assess exposure in their environments.

Recommended defensive actions

  • Verify the affected packages @insumermodel/mppx-condition-gate and @insumermodel/mppx-token-gate are not used in environments where free access could be exploited.
  • Assess exposure by checking if the affected versions are in use.
  • Update to the fixed versions 3.0.0 for @insumermodel/mppx-condition-gate and 1.0.4 for @insumermodel/mppx-token-gate.
  • Monitor for potential exploitation attempts using the in-process cache.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The source corpus provides details on the vulnerability in the mppx-condition-gate packages, including the impact, affected versions 3.0.0 and 1.0.4 for @insumermodel/mppx-condition-gate and @insumermodel/mppx-token-gate, and fixed versions. The vulnerability allows free access to paid routes without proving control of the wallet. Defenders must verify the affected packages are not used in environments where free access could be exploited. Exposure could allow unauthorized access to paid routes. Remediation priority is high for The m

Sources and references

Verified primary and authoritative sources

  • CVE-2026-104891 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-104891

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-104891 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-104891

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • mppx-condition-gate: Free-access path grants on a self-declared wallet without proving control

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-jg6q-3qfh-r9f8.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/douglasborthwick-crypto/mppx-condition-gate/security/advisories/GHSA-jg6q-3qfh-r9f8

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/insumerapi/mppx-condition-gate/security/advisories/GHSA-jg6q-3qfh-r9f8

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/insumerapi/mppx-condition-gate/commit/b1d9935a57ba6d32da49eead1bfb459ad0cd55ab

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/insumerapi/mppx-condition-gate/commit/ec43a2fcd443a0fa102b6d4203abed2b785bd954

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/douglasborthwick-crypto/mppx-condition-gate

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.