Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-74wf-7q7r-hjxr

Опубликовано: 23 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

Capgo before 12.128.2 contains a credential validation vulnerability in the POST /functions/v1/private/validate_password_compliance endpoint that is callable using only the public Supabase key without authentication. The endpoint is CORS-permissive with wildcard origin allowance and lacks rate limiting, enabling attackers to perform password spraying and credential stuffing attacks to compromise user accounts.

Capgo before 12.128.2 contains a credential validation vulnerability in the POST /functions/v1/private/validate_password_compliance endpoint that is callable using only the public Supabase key without authentication. The endpoint is CORS-permissive with wildcard origin allowance and lacks rate limiting, enabling attackers to perform password spraying and credential stuffing attacks to compromise user accounts.

EPSS

Процентиль: 33%
0.004
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-307

Связанные уязвимости

CVSS3: 5.3
nvd
3 месяца назад

Capgo before 12.128.2 contains a credential validation vulnerability in the POST /functions/v1/private/validate_password_compliance endpoint that is callable using only the public Supabase key without authentication. The endpoint is CORS-permissive with wildcard origin allowance and lacks rate limiting, enabling attackers to perform password spraying and credential stuffing attacks to compromise user accounts.

EPSS

Процентиль: 33%
0.004
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-307