PT-2026-51037 · Cap Go · Cap-Go
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
A cross-tenant authorization bypass exists in PostgREST endpoints. This issue allows API keys with organization-level read permissions to access webhook secrets and delivery logs belonging to other tenants. An attacker can query the "/webhooks" and "/webhook deliveries" endpoints to exfiltrate HMAC (Hash-based Message Authentication Code) signing secrets and delivery payloads, which can be used to forge webhook events against victim organizations.
Recommendations
Update to version 12.128.2 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go