
Your read-only API key can cancel production builds. CVE-2026-56280 in Cap-go: GET /build/logs/:jobId streams output over SSE but also registers an abort listener. No permission check. Read scope becomes destroy scope. Here's what to check Wednesday:
Post summary
The message discloses a privilege‑escalation flaw in Cap‑go where a read‑only API key can cancel builds due to a missing permission check on the logs endpoint.
