Unrated severityNVD Advisory· Published Jun 24, 2026· Updated Jun 24, 2026
Capgo - Webhook Signing Secret Disclosure via Non-Admin API Key
CVE-2026-56244
Description
Capgo before 12.128.2 allows non-admin API keys to read webhook signing secrets via Supabase REST due to insufficient row-level security policies on the webhooks table. Attackers can retrieve the webhook secret and forge valid X-Capgo-Signature headers to send authenticated webhook events to configured receivers, breaking webhook authenticity and integrity.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/Cap-go/capgo/security/advisories/GHSA-qrrx-x3qf-x87vmitrevendor-advisory
- www.vulncheck.com/advisories/capgo-webhook-signing-secret-disclosure-via-non-admin-api-keymitrethird-party-advisory
News mentions
0No linked articles in our index yet.