PT-2026-51767 · Cap Go · Cap-Go
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
The
middlewareKey() function fails to enforce limited to orgs and limited to apps constraints on subkeys provided through the x-limited-key-id header. This allows attackers to bypass subkey scope restrictions by referencing their own subkeys, which results in downstream route handlers utilizing the unrestricted parent key instead of the intended scoped subkey.Recommendations
Update to version 12.128.2 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go