Summary
GET /v1/contributors/:login/profile and the gittensory_get_contributor_profile MCP tool skip the contributor-scoped access check that every sibling endpoint enforces. Any authenticated session/API/MCP token holder can read any contributor's profile; for confirmed Gittensor miners that exposes alphaPerDay, taoPerDay, usdPerDay (and the hotkey on the REST path). Authenticated cross-contributor disclosure, CWE-284 / IDOR.
Details
In src/api/routes.ts the profile handler returns buildContributorProfile(...) with no requireContributorAccess call. Every sibling (/decision-pack, /repos/:owner/:repo/decision, etc.) gates and 403s on a cross-contributor request — the profile route is the only omission. buildContributorProfile (src/signals/engine.ts) embeds hotkey and the three *PerDay fields for any confirmed miner.
The MCP tool getContributorProfile (src/mcp/server.ts) also omits requireContributorAccess. Its redactSensitiveForMcp filter only strips keys matching hotkey|coldkey|wallet|private_key|privateKey|mnemonic, so the hotkey is dropped but alphaPerDay/taoPerDay/usdPerDay pass through.
The codebase treats these as secret everywhere else — decision-pack.ts destructures the hotkey out before serving, and three sanitizers scrub hotkey/wallet from AI/comment output — which is why this is an oversight, not by-design.
Exposure: REST → hotkey + 3 financial fields; MCP → 3 financial fields (hotkey redacted).
PoC
- Get any valid session/API/MCP token.
- Pick a target
login that is a confirmed miner.
GET /v1/contributors/{target}/profile → 200 with gittensor.hotkey, alphaPerDay, taoPerDay, usdPerDay.
GET /v1/contributors/{target}/decision-pack (same token) → 403, proving the missing gate.
- MCP
gittensory_get_contributor_profile with {target} → result includes the three *PerDay fields.
Impact
Any token holder can enumerate other miners' daily TAO/alpha/USD revenue (plus hotkey via REST) without authorization. All miners with snapshot data are affected.
References
Summary
GET /v1/contributors/:login/profileand thegittensory_get_contributor_profileMCP tool skip the contributor-scoped access check that every sibling endpoint enforces. Any authenticated session/API/MCP token holder can read any contributor's profile; for confirmed Gittensor miners that exposesalphaPerDay,taoPerDay,usdPerDay(and thehotkeyon the REST path). Authenticated cross-contributor disclosure, CWE-284 / IDOR.Details
In
src/api/routes.tsthe profile handler returnsbuildContributorProfile(...)with norequireContributorAccesscall. Every sibling (/decision-pack,/repos/:owner/:repo/decision, etc.) gates and 403s on a cross-contributor request — the profile route is the only omission.buildContributorProfile(src/signals/engine.ts) embedshotkeyand the three*PerDayfields for any confirmed miner.The MCP tool
getContributorProfile(src/mcp/server.ts) also omitsrequireContributorAccess. ItsredactSensitiveForMcpfilter only strips keys matchinghotkey|coldkey|wallet|private_key|privateKey|mnemonic, so the hotkey is dropped butalphaPerDay/taoPerDay/usdPerDaypass through.The codebase treats these as secret everywhere else —
decision-pack.tsdestructures the hotkey out before serving, and three sanitizers scrub hotkey/wallet from AI/comment output — which is why this is an oversight, not by-design.Exposure: REST → hotkey + 3 financial fields; MCP → 3 financial fields (hotkey redacted).
PoC
loginthat is a confirmed miner.GET /v1/contributors/{target}/profile→ 200 withgittensor.hotkey,alphaPerDay,taoPerDay,usdPerDay.GET /v1/contributors/{target}/decision-pack(same token) → 403, proving the missing gate.gittensory_get_contributor_profilewith{target}→ result includes the three*PerDayfields.Impact
Any token holder can enumerate other miners' daily TAO/alpha/USD revenue (plus hotkey via REST) without authorization. All miners with snapshot data are affected.
References