Executive brief
Capgo, a platform for managing app updates and webhooks, suffered from a security flaw where a customer's read-only API key could be used to access the private data of other customers. This allowed unauthorized access to sensitive webhook signing secrets and delivery logs belonging to different organizations. An attacker could use this stolen information to forge legitimate-looking notifications, potentially tricking a victim's systems into performing unauthorized actions or exposing private user data.
Technical details
A cross-tenant authorization bypass exists in Capgo's Supabase PostgREST endpoints due to improper Row Level Security (RLS) or scoping enforcement. Specifically, API keys restricted to a single organization (limited_to_orgs) fail to have those restrictions honored when querying the 'webhooks' and 'webhook_deliveries' tables. An authenticated attacker with a valid read-scoped API key can query these endpoints to retrieve HMAC signing secrets (whsec_*) and request/response payloads belonging to other tenants. This enables the exfiltration of PII and the ability to compute valid signatures for forged webhook events. The issue is addressed in version 12.128.2.
Affected products
- Capgo Capgo < 12.128.2
Timeline
- 2026-03-17: advisory: GitHub Security Advisory published
- 2026-06-19: disclosed: CVE published to NVD