CVE-2026-56244

HIGH

Capgo - Webhook Signing Secret Disclosure via Non-Admin API Key

Title source: cna
STIX 2.1

Description

Capgo before 12.128.2 allows non-admin API keys to read webhook signing secrets via Supabase REST due to insufficient row-level security policies on the webhooks table. Attackers can retrieve the webhook secret and forge valid X-Capgo-Signature headers to send authenticated webhook events to configured receivers, breaking webhook authenticity and integrity.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-qrrx-x3qf-x87v)
https://github.com/Cap-go/capgo/security/advisories/GHSA-qrrx-x3qf-x87v
Third Party Advisory third-party-advisory
VulnCheck Advisory: Capgo - Webhook Signing Secret Disclosure via Non-Admin API Key
https://www.vulncheck.com/advisories/capgo-webhook-signing-secret-disclosure-via-non-admin-api-key

Scores

CVSS v3 7.1
EPSS 0.0019
EPSS Percentile 9.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
Capgo/Capgo < 12.128.2
Capgo/Capgo 12.128.2
Published Jun 24, 2026
Tracked Since Jun 24, 2026