Privilege Inversion Vulnerability in Cap-go Product by Cap-go
CVE-2026-56280
7.1HIGH
What is CVE-2026-56280?
Cap-go versions prior to 12.128.2 exhibit a privilege inversion vulnerability that permits holders of read-only API keys to terminate ongoing native build processes. This occurs through the GET /build/logs/:jobId endpoint, which incorrectly leverages the privileged BUILDER_API_KEY for aborting operations when a client disconnects. This flaw facilitates malicious actors in persistently undermining native build processes and CI/CD workflows, by connecting to the log stream and then severing the connection, effectively circumventing mandatory permission checks associated with build cancellation.
Affected Version(s)
capgo 0 < 12.128.2
capgo 12.128.2
