CVE-2026-56280: Cap-go - Privilege Inversion in Build Log Stream via SSE Disconnect
Cap-go before 12.128.2 contains a privilege inversion vulnerability in GET /build/logs/:jobId that allows read-only API key holders to cancel running native builds. The endpoint registers an abort listener on the SSE stream that unconditionally invokes cancelBuildOnDisconnect() using the privileged server-side BUILDERAPIKEY when clients disconnect, bypassing the app.buildnative permission check required by the explicit POST /build/cancel/:jobId endpoint. Attackers with read-only API keys can repeatedly disrupt native build operations and CI/CD workflows by opening the log stream and dropping the connection.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cap-goto a version that resolves this vulnerability.Fixed in 12.128.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56280?
The severity of CVE-2026-56280 is rated high at 7.1.
How do I fix CVE-2026-56280?
To fix CVE-2026-56280, update Cap-go to version 12.128.2 or later.
What type of vulnerability is CVE-2026-56280?
CVE-2026-56280 is a privilege inversion vulnerability.
What impact does CVE-2026-56280 have on API key holders?
CVE-2026-56280 allows read-only API key holders to cancel running native builds.
What endpoint is affected by CVE-2026-56280?
The endpoint affected by CVE-2026-56280 is GET /build/logs/:jobId.