PT-2026-51770 · Supabase · Cap-Go
CVSS v4.0
8.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Supabase Capgo versions prior to 12.128.2
Description
An authorization bypass exists in the
record build time() RPC function, which is configured as SECURITY DEFINER (a property that allows a function to execute with the privileges of the user who created it rather than the user calling it). Unauthenticated attackers can exploit this by sending a request to the 'POST /rest/v1/rpc/record build time' endpoint using a public API key. This allows the insertion of arbitrary build-time records to poison billing and quota data for any organization, potentially leading to resource exhaustion and cross-tenant billing manipulation.Recommendations
Update to version 12.128.2 or later.
As a temporary mitigation, restrict access to the 'POST /rest/v1/rpc/record build time' endpoint.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go