Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Gittensory mcp: Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data

0
Medium
Published: 07/09/2026 (07/09/2026, 13:44:51 UTC)
Source: GCVE Database
Product: @jsonbored/gittensory-mcp

Description

A missing contributor-scoped access control in the Gittensory MCP tool and REST API profile endpoint allows any authenticated token holder to access other contributors' profile data. This includes sensitive financial metrics such as alphaPerDay, taoPerDay, usdPerDay, and in the REST API, the hotkey. Other endpoints enforce proper access controls, making this an oversight rather than by design. The vulnerability enables unauthorized disclosure of miner financial data and hotkey information via the profile endpoint and MCP tool.

CVSS v3.1

Score 6.5medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected software

npmghsa
@jsonbored/gittensory-mcp
Affected versions
<=0.1.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/10/2026, 10:23:39 UTC

Technical Analysis

The Gittensory MCP tool and the REST API endpoint GET /v1/contributors/:login/profile lack the contributor-scoped access control that sibling endpoints enforce. This omission allows any authenticated session, API, or MCP token holder to retrieve any contributor's profile data, including sensitive financial fields (alphaPerDay, taoPerDay, usdPerDay) and the hotkey in the REST API path. The MCP tool redacts the hotkey but still exposes the financial data. This is classified as an IDOR (CWE-284) vulnerability due to missing authorization checks on these endpoints. Other endpoints properly enforce access restrictions, returning 403 on unauthorized access, highlighting this as an accidental omission.

Potential Impact

Any authenticated user with a valid session, API, or MCP token can enumerate other contributors' financial earnings data and, via the REST API, the hotkey. This unauthorized disclosure compromises contributor privacy and could facilitate further attacks or misuse of sensitive financial and key information. The vulnerability does not affect availability or integrity but results in high confidentiality impact for the exposed data.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict token issuance and monitor usage to limit exposure. Avoid sharing tokens broadly and consider implementing additional access controls or request filtering on the affected endpoints to prevent unauthorized profile data access.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-382c-vx95-w3p5
Osv Schema Version
1.4.0
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
MODERATE
Cvss Version
3.1

Threat ID: 6a50bac768715ace4358916f

Added to database: 07/10/2026, 09:26:31 UTC

Last enriched: 07/10/2026, 10:23:39 UTC

Last updated: 07/31/2026, 12:27:13 UTC

Views: 63

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses