PT-2026-51040 · Cap Go · Cap-Go

Judel777

·

Publicado

2026-06-19

·

Atualizado

2026-06-19

·

CVE-2026-56082

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST RPC function public.record build time, which is granted to the anon role and callable with only the public Supabase publishable (sb publishable *) anon key. An unauthenticated attacker can insert rows into public.build logs for arbitrary organizations and, because the function uses ON CONFLICT (build id, org id) DO UPDATE, can overwrite existing usage/billing records by reusing the same build id for a target org. This enables cross-tenant tampering of billing build logs and financial-impact denial of service by inflating billable build time.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-56082

Produtos afetados

Cap-Go