PT-2026-51406 · Cap Go · Cap-Go
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Cap-go versions prior to 12.128.2
Description
A privilege inversion issue exists in the 'GET /build/logs/:jobId' endpoint. This endpoint utilizes Server-Sent Events (SSE) to stream output and registers an abort listener that invokes the
cancelBuildOnDisconnect() function using a privileged server-side BUILDER API KEY upon client disconnection. This process bypasses the app.build native permission check normally required by the 'POST /build/cancel/:jobId' endpoint. Consequently, users with read-only API keys can disrupt native build operations and CI/CD workflows by repeatedly opening the log stream and dropping the connection.Recommendations
Update to version 12.128.2 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go