Skip to content

MCPA-2026-0041

mediumauth-missingCVSS 6.5

Gittensory MCP tool leaks miner financial data via missing contributor-scoped access control

@jsonbored/gittensory-mcp (npm) through 0.1.0: the gittensory_get_contributor_profile MCP tool (and the matching GET /v1/contributors/:login/profile endpoint) skips the contributor-scoped access check enforced by every sibling endpoint — any authenticated session/API/MCP token holder can read any contributor's profile, exposing miner earnings data (alphaPerDay, taoPerDay, usdPerDay). Patched upstream (commit 811ef5f); no fixed npm release was available at publication.

Affected packages

EcosystemPackageAffected versions
npm@jsonbored/gittensory-mcp
>= 0, <= 0.1.0

Identifiers

GHSA-382c-vx95-w3p5CWE-284

References

Timeline

  • Published: 2026-07-09

← All advisories