PT-2026-56432 · Cap Go+1 · Cap-Go+1
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
An information disclosure issue exists in the Supabase PostgREST RPC function
public.get total metrics(org id). This function is accessible to the anon role using only the public sb publishable * key. An unauthenticated attacker can verify the existence of organizations and leak sensitive usage metrics, such as Monthly Active Users (MAU), bandwidth, and install counts, by sending POST requests to the '/rest/v1/rpc/get total metrics' endpoint using valid organization UUIDs.Recommendations
Update to version 12.128.2 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go
Postgres