{"id":"GHSA-382c-vx95-w3p5","aliases":[],"url":"https://o3.security/vulnerability/GHSA-382c-vx95-w3p5","summary":"Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data","details":"### Summary\n \n`GET /v1/contributors/:login/profile` and the `gittensory_get_contributor_profile` MCP tool skip the contributor-scoped access check that every sibling endpoint enforces. Any authenticated session/API/MCP token holder can read any contributor's profile; for confirmed Gittensor miners that exposes `alphaPerDay`, `taoPerDay`, `usdPerDay` (and the `hotkey` on the REST path). Authenticated cross-contributor disclosure, CWE-284 / IDOR.\n \n### Details\n \nIn `src/api/routes.ts` the profile handler returns `buildContributorProfile(...)` with no `requireContributorAccess` call. Every sibling (`/decision-pack`, `/repos/:owner/:repo/decision`, etc.) gates and 403s on a cross-contributor request — the profile route is the only omission. `buildContributorProfile` (`src/signals/engine.ts`) embeds `hotkey` and the three `*PerDay` fields for any confirmed miner.\n \nThe MCP tool `getContributorProfile` (`src/mcp/server.ts`) also omits `requireContributorAccess`. Its `redactSensitiveForMcp` filter only strips keys matching `hotkey|coldkey|wallet|private_key|privateKey|mnemonic`, so the hotkey is dropped but `alphaPerDay`/`taoPerDay`/`usdPerDay` pass through.\n \nThe codebase treats these as secret everywhere else — `decision-pack.ts` destructures the hotkey out before serving, and three sanitizers scrub hotkey/wallet from AI/comment output — which is why this is an oversight, not by-design.\n \nExposure: REST → hotkey + 3 financial fields; MCP → 3 financial fields (hotkey redacted).\n \n### PoC\n \n1. Get any valid session/API/MCP token.\n2. Pick a target `login` that is a confirmed miner.\n3. `GET /v1/contributors/{target}/profile` → 200 with `gittensor.hotkey`, `alphaPerDay`, `taoPerDay`, `usdPerDay`.\n4. `GET /v1/contributors/{target}/decision-pack` (same token) → 403, proving the missing gate.\n5. MCP `gittensory_get_contributor_profile` with `{target}` → result includes the three `*PerDay` fields.\n### Impact\n \nAny token holder can enumerate other miners' daily TAO/alpha/USD revenue (plus hotkey via REST) without authorization. All miners with snapshot data are affected.","published":"2026-07-09T13:44:51Z","modified":"2026-07-09T14:00:37.476741418Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@jsonbored/gittensory-mcp","fixedVersion":null}],"fix":{"url":"https://github.com/JSONbored/gittensory/commit/811ef5fb9d748170011f8854d88c64627ad666a0","label":"JSONbored/gittensory@811ef5f"},"references":[{"type":"WEB","url":"https://github.com/JSONbored/gittensory/security/advisories/GHSA-382c-vx95-w3p5"},{"type":"WEB","url":"https://github.com/JSONbored/gittensory/commit/811ef5fb9d748170011f8854d88c64627ad666a0"},{"type":"PACKAGE","url":"https://github.com/JSONbored/gittensory"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T14:00:37.476741418Z"}}