Executive brief
Cap-go capgo.app is a mobile app deployment platform that uses API keys for authentication and authorization. A flaw in API key rotation allows users with basic apikey_manager permissions to rotate higher-privileged org_super_admin keys and steal their plaintext credentials, escalating their account privileges. An attacker can authenticate as the compromised high-privilege account and gain administrative control of the organization.
Technical details
The vulnerability is an improper privilege management flaw in the API key rotation endpoint (PUT /apikey). The authorization logic checks only whether the caller can manage API keys and whether the target key's organization is manageable, but fails to validate that the caller's role dominates the target key's role. An authenticated attacker with apikey_manager role can enumerate sibling keys belonging to the same user via the GET endpoint, select a higher-privileged org_super_admin key, and rotate it through PUT, receiving the plaintext replacement secret. The affected code is in supabase/functions/_backend/public/apikey/scope.ts and put.ts; fix requires role-dominance validation before rotation.
Affected products
- Cap-go capgo.app before 12.267.1
Timeline
- 2026-09-26: disclosed
- 2026-09-26: patched: fixed in version 12.267.1