PT-2026-51770 · Supabase · Cap-Go

·

CVE-2026-56245

·

Published

2026-06-24

·

Updated

2026-06-24

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Supabase Capgo versions prior to 12.128.2
Description An authorization bypass exists in the record build time() RPC function, which is configured as SECURITY DEFINER (a property that allows a function to execute with the privileges of the user who created it rather than the user calling it). Unauthenticated attackers can exploit this by sending a request to the 'POST /rest/v1/rpc/record build time' endpoint using a public API key. This allows the insertion of arbitrary build-time records to poison billing and quota data for any organization, potentially leading to resource exhaustion and cross-tenant billing manipulation.
Recommendations Update to version 12.128.2 or later. As a temporary mitigation, restrict access to the 'POST /rest/v1/rpc/record build time' endpoint.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56245
GHSA-42F8-V563-5763

Affected Products

Cap-Go