Capgo before 12.128.2 contains an authorization bypass...
Moderate severity
Unreviewed
Published
Jun 20, 2026
to the GitHub Advisory Database
•
Updated Jun 20, 2026
Description
Published by the National Vulnerability Database
Jun 20, 2026
Published to the GitHub Advisory Database
Jun 20, 2026
Last updated
Jun 20, 2026
Capgo before 12.128.2 contains an authorization bypass vulnerability in webhook management endpoints that allows non-expiring API keys to bypass the require_apikey_expiration organization policy. The checkWebhookPermission function fails to call apikeyHasOrgRightWithPolicy, enabling attackers with legacy non-expiring keys to list, create, and delete webhooks despite explicit organizational policy requiring key expiration.
References