PT-2026-51502 · Cap Go · Cap-Go
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
An issue exists in the 'POST /functions/v1/private/validate password compliance' endpoint that allows credential validation without authentication, requiring only the public Supabase key. The endpoint is CORS-permissive with wildcard origin allowance and lacks rate limiting, which enables attackers to conduct password spraying and credential stuffing attacks to compromise user accounts. Cross-Origin Resource Sharing (CORS) is a mechanism that allows restricted resources on a web page to be requested from another domain outside the domain from which the first resource was served.
Recommendations
Update to version 12.128.2 or later.
Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go