PT-2026-51044 · Cap Go+1 · Cap-Go+1
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
An information disclosure issue exists in Supabase PostgREST RPC endpoints "is trial org" and "is paying org". Unauthenticated attackers can use the public
sb publishable key to invoke these endpoints and enumerate organizations. By analyzing distinguishable return values, attackers can determine if an organization exists and identify its billing status to profile paying customers.Recommendations
Update to version 12.128.2 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go
Postgres