PT-2026-51406 · Cap Go · Cap-Go

·

CVE-2026-56280

·

Published

2026-06-22

·

Updated

2026-06-24

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Cap-go versions prior to 12.128.2
Description A privilege inversion issue exists in the 'GET /build/logs/:jobId' endpoint. This endpoint utilizes Server-Sent Events (SSE) to stream output and registers an abort listener that invokes the cancelBuildOnDisconnect() function using a privileged server-side BUILDER API KEY upon client disconnection. This process bypasses the app.build native permission check normally required by the 'POST /build/cancel/:jobId' endpoint. Consequently, users with read-only API keys can disrupt native build operations and CI/CD workflows by repeatedly opening the log stream and dropping the connection.
Recommendations Update to version 12.128.2 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56280
GHSA-95G7-XWWX-J737

Affected Products

Cap-Go