Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-56311

Опубликовано: 22 июн. 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.get_current_plan_max_org RPC function that allows unauthenticated attackers to retrieve arbitrary organization plan limits. Attackers can call the RPC endpoint with any organization UUID using only the public Supabase key to disclose billing information including MAU, bandwidth, storage, and build time limits for any organization.

EPSS

Процентиль: 30%
0.00364
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-285

EPSS

Процентиль: 30%
0.00364
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-285