PT-2026-51407 · Cap Go · Cap-Go
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
A weak parsing issue exists in the
x-limited-key-id header. Remote attackers can bypass subkey enforcement by submitting duplicate headers, zero, or malformed values that result in falsy values or NaN (Not-a-Number, a value representing an undefined or unrepresentable numerical result). This allows the attacker to disable limited key scoping and execute requests using the main API key context instead of the restricted subkey permissions.Recommendations
Update to version 12.128.2 or later.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go