Impact
Capgo before version 12.128.2 has an information disclosure vulnerability in its Supabase PostgREST global_stats endpoint. The flaw allows unauthenticated attackers to read sensitive financial and operational metrics such as monthly recurring revenue, total revenue, plan‑tier revenue breakdown, customer counts, and operational telemetry by sending requests to /rest/v1/global_stats using only the public API key.
Affected Systems
Deployments of the Capgo platform that expose the PostgREST /rest/v1/global_stats endpoint and use a public API key are affected. The vulnerability exists in all versions prior to 12.128.2; upgrades to that release or later remove the flaw.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is via the network to the exposed endpoint; attackers can reach it remotely using only the public API key, making exploitation straightforward if the endpoint remains publicly reachable.
OpenCVE Enrichment