Advisories for Npm/@Insumermodel/Mppx-Condition-Gate package

2026

mppx-condition-gate: Free-access path grants on a self-declared wallet without proving control

Both packages wrap an mppx payment method so that a wallet meeting on-chain conditions is granted free access instead of being charged. The free-access path reads the payer address from credential.source — a client-supplied DID in the payment credential — asks InsumerAPI whether that address satisfies the configured conditions, and on a pass returns a successful receipt without ever calling the wrapped payment verifier. Nothing in that path establishes that …