Tag
Information Disclosure in Capgo Supabase Integration via RPC Function
2 TTPs 1 CVEAn information disclosure vulnerability in Capgo (Cap-go/capgo) before version 12.128.2 allows unauthenticated attackers to enumerate organization existence. This flaw resides within the Supabase PostgREST SECURITY DEFINER RPC function 'public.rescind_invitation', which returns distinct error messages (NO_ORG vs. NO_RIGHTS) when called with only a publishable API key. This enables attackers to discover valid organization IDs, increasing the attack surface for targeted phishing or social engineering campaigns.
CVE-2026-56238 - Capgo Supabase PostgREST Information Disclosure
1 rule 2 TTPs 1 CVEAn information disclosure vulnerability (CVE-2026-56238) in Capgo before 12.128.2's Supabase PostgREST global_stats endpoint allows unauthenticated attackers to retrieve sensitive financial and operational metrics using a public API key.
CVE-2026-56226 - Capgo Unauthenticated Data Exposure via Supabase PostgREST RPC
1 rule 2 TTPs 1 CVECVE-2026-56226 details a high-severity vulnerability in Capgo versions prior to 12.128.2 that exposes a Supabase PostgREST RPC function, `public.get_orgs_v6`, to unauthenticated attackers, allowing them to retrieve sensitive user organization membership and PII by supplying an arbitrary user UUID.