Unrated severityNVD Advisory· Published Jul 11, 2026· Updated Jul 13, 2026
Capgo - Unauthenticated API Key Metadata Disclosure via SECURITY DEFINER RPC Function
CVE-2026-56303
Description
Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function marked SECURITY DEFINER and executable by the anon role. Unauthenticated attackers can call this function via the /rest/v1/rpc/find_apikey_by_value endpoint to retrieve sensitive API key metadata including user_id, mode, org scoping, and expiration details when supplied a valid key value.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/Cap-go/capgo/security/advisories/GHSA-2xjq-h43m-592fmitrevendor-advisory
- www.vulncheck.com/advisories/capgo-unauthenticated-api-key-metadata-disclosure-via-security-definer-rpc-functionmitrethird-party-advisory
News mentions
0No linked articles in our index yet.