MCPA-2026-0041
mediumauth-missingCVSS 6.5
Gittensory MCP tool leaks miner financial data via missing contributor-scoped access control
@jsonbored/gittensory-mcp (npm) through 0.1.0: the gittensory_get_contributor_profile MCP tool (and the matching GET /v1/contributors/:login/profile endpoint) skips the contributor-scoped access check enforced by every sibling endpoint — any authenticated session/API/MCP token holder can read any contributor's profile, exposing miner earnings data (alphaPerDay, taoPerDay, usdPerDay). Patched upstream (commit 811ef5f); no fixed npm release was available at publication.
Affected packages
| Ecosystem | Package | Affected versions |
|---|---|---|
| npm | @jsonbored/gittensory-mcp | >= 0, <= 0.1.0 |
Identifiers
GHSA-382c-vx95-w3p5CWE-284
References
- advisory https://github.com/JSONbored/gittensory/security/advisories/GHSA-382c-vx95-w3p5
- fix https://github.com/JSONbored/gittensory/commit/811ef5fb9d748170011f8854d88c64627ad666a0
Timeline
- Published: 2026-07-09