Gittensory mcp: Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data
A missing contributor-scoped access control in the Gittensory MCP tool and REST API profile endpoint allows any authenticated token holder to access other contributors' profile data. This includes sensitive financial metrics such as alphaPerDay, taoPerDay, usdPerDay, and in the REST API, the hotkey. Other endpoints enforce proper access controls, making this an oversight rather than by design. The vulnerability enables unauthorized disclosure of miner financial data and hotkey information via the profile endpoint and MCP tool.
AI Analysis
Technical Summary
The Gittensory MCP tool and the REST API endpoint GET /v1/contributors/:login/profile lack the contributor-scoped access control that sibling endpoints enforce. This omission allows any authenticated session, API, or MCP token holder to retrieve any contributor's profile data, including sensitive financial fields (alphaPerDay, taoPerDay, usdPerDay) and the hotkey in the REST API path. The MCP tool redacts the hotkey but still exposes the financial data. This is classified as an IDOR (CWE-284) vulnerability due to missing authorization checks on these endpoints. Other endpoints properly enforce access restrictions, returning 403 on unauthorized access, highlighting this as an accidental omission.
Potential Impact
Any authenticated user with a valid session, API, or MCP token can enumerate other contributors' financial earnings data and, via the REST API, the hotkey. This unauthorized disclosure compromises contributor privacy and could facilitate further attacks or misuse of sensitive financial and key information. The vulnerability does not affect availability or integrity but results in high confidentiality impact for the exposed data.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict token issuance and monitor usage to limit exposure. Avoid sharing tokens broadly and consider implementing additional access controls or request filtering on the affected endpoints to prevent unauthorized profile data access.
Gittensory mcp: Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data
Description
A missing contributor-scoped access control in the Gittensory MCP tool and REST API profile endpoint allows any authenticated token holder to access other contributors' profile data. This includes sensitive financial metrics such as alphaPerDay, taoPerDay, usdPerDay, and in the REST API, the hotkey. Other endpoints enforce proper access controls, making this an oversight rather than by design. The vulnerability enables unauthorized disclosure of miner financial data and hotkey information via the profile endpoint and MCP tool.
CVSS v3.1
Score 6.5medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Gittensory MCP tool and the REST API endpoint GET /v1/contributors/:login/profile lack the contributor-scoped access control that sibling endpoints enforce. This omission allows any authenticated session, API, or MCP token holder to retrieve any contributor's profile data, including sensitive financial fields (alphaPerDay, taoPerDay, usdPerDay) and the hotkey in the REST API path. The MCP tool redacts the hotkey but still exposes the financial data. This is classified as an IDOR (CWE-284) vulnerability due to missing authorization checks on these endpoints. Other endpoints properly enforce access restrictions, returning 403 on unauthorized access, highlighting this as an accidental omission.
Potential Impact
Any authenticated user with a valid session, API, or MCP token can enumerate other contributors' financial earnings data and, via the REST API, the hotkey. This unauthorized disclosure compromises contributor privacy and could facilitate further attacks or misuse of sensitive financial and key information. The vulnerability does not affect availability or integrity but results in high confidentiality impact for the exposed data.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict token issuance and monitor usage to limit exposure. Avoid sharing tokens broadly and consider implementing additional access controls or request filtering on the affected endpoints to prevent unauthorized profile data access.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-382c-vx95-w3p5
- Osv Schema Version
- 1.4.0
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a50bac768715ace4358916f
Added to database: 07/10/2026, 09:26:31 UTC
Last enriched: 07/10/2026, 10:23:39 UTC
Last updated: 07/31/2026, 12:27:13 UTC
Views: 63
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.