Junglewise Threat Intelligence

CVE-2026-56245: Supabase Capgo authorization bypass in record_build_time RPC

CVE-2026-56245 · Severity: high · CVSS 8.2 · Published 2026-06-24

Executive brief

A security flaw in Supabase Capgo allows unauthorized individuals to manipulate billing and usage data for any organization using the service. By sending specially crafted requests with a public API key, an attacker can falsely inflate build-time records, potentially leading to unexpected charges, exhausted service quotas, or service disruptions for victim companies. This issue affects the integrity of the platform's accounting system and could be used to maliciously target specific customers.

Technical details

The vulnerability exists in the 'record_build_time' Remote Procedure Call (RPC) function, which is defined with 'SECURITY DEFINER' privileges and explicitly granted to 'anon' and 'authenticated' roles. The function performs an 'INSERT ... ON CONFLICT DO UPDATE' operation into the 'public.build_logs' table using attacker-supplied parameters (p_org_id, p_user_id, p_build_id) without verifying the caller's identity or membership in the target organization. An unauthenticated attacker can exploit this by sending a POST request to the '/rest/v1/rpc/record_build_time' endpoint using a public API key. This allows for cross-tenant data injection, enabling attackers to inflate build-time metrics, manipulate billing credits, or cause resource exhaustion by flooding the logs. The issue is resolved in version 12.128.2 by implementing proper authorization checks and restricting function access.

Affected products

  • Supabase Capgo < 12.128.2

Timeline

  • 2026-03-17: advisory: Initial GitHub Security Advisory published
  • 2026-06-24: disclosed: CVE-2026-56245 published to NVD

References