Cap-go capgo.app
23 known vulnerabilities in Cap-go capgo.app, 2 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-100629 CVSS 7.0 high Capgo (capgo.app backend) before 12.127.5 contains an authorization flaw in the PATCH /private/role_bindings/:binding_id endpoint. The…
- CVE-2026-100628 CVSS 8.7 high capgo.app before 12.128.12 fails to enforce an organization's API key expiration policy when creating app-scoped API keys. In the POST…
- CVE-2026-100627 CVSS 7.2 high Capgo (Cap-go/capgo.app) server backend Supabase functions contain an incorrect authorization flaw in the API-key bundle promotion path…
- CVE-2026-100626 CVSS 5.3 medium capgo through 12.128.2 contains an insecure direct object reference vulnerability in the PUT /app/:appId endpoint that accepts…
- CVE-2026-100625 CVSS 8.7 high Capgo (capgo.app) exposes a native build TUS upload proxy (supabase/functions/_backend/public/build/upload.ts) that authorizes a caller…
- CVE-2026-100624 CVSS 5.3 medium Capgo.app before 12.264.5 does not enforce upload expiry or build lifecycle state in the /build/upload/:jobId TUS proxy endpoint. When a…
- CVE-2026-100623 CVSS 8.7 high Capgo (capgo.app) exposes the legacy membership table public.org_users directly through Supabase PostgREST. The table's row-level security…
- CVE-2026-100622 CVSS 8.7 high capgo.app through 12.129.0 fails to verify deletion status when serving cached bundle artifacts from the public file read endpoint…
- CVE-2026-100621 CVSS 5.3 medium Capgo (capgo.app) contains an incomplete access-control/content-lock enforcement issue affecting all versions; no patch is available at…
- CVE-2026-100619 CVSS 8.7 high Capgo (capgo.app) blocks direct user inserts into the public.manifest table with a RESTRICTIVE row-level security policy, but that…
- CVE-2026-100618 CVSS 8.7 high Capgo (capgo.app) is affected by an authorization flaw in the app icon update path. The PUT /app/:id endpoint accepts a user-controlled…
- CVE-2026-100617 CVSS 8.7 high Cap-go capgo.app fails to validate that principals in channel_permission_overrides belong to the organization, allowing authenticated…
- CVE-2026-100616 CVSS 7.0 high capgo.app is an over-the-air update platform for Capacitor apps. In all versions prior to a fix, the row-level security UPDATE policy on…
- CVE-2026-100615 CVSS 8.7 high Cap-go capgo.app before 12.267.1 fails to validate target API key privilege during rotation, allowing an apikey_manager to rotate a…
- CVE-2026-100614 CVSS 8.7 high Capgo before 12.244.1 contains a cross-tenant integrity vulnerability in the metadata-cleaning worker that trusts image object keys from…
- CVE-2026-100613 CVSS 6.0 medium capgo.app is an over-the-air (OTA) update platform for Capacitor apps. In all versions up to and including the current release (no patch…
- CVE-2026-100612 CVSS 8.6 high Capgo (capgo.app) through version 12.261.0 contains an incomplete access-control fix for the public.sso_providers table. Migration…
- CVE-2026-100611 CVSS 7.1 high Capgo (capgo.app backend, versions ≤ 12.261.0) improperly restricts which roles the apikey_manager organization role may bind to newly…
- CVE-2026-88864 CVSS 9.3 critical Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST. A holder of…
- CVE-2026-88863 CVSS 8.6 high capgo.app (npm package `capgo`) through version 12.207.1 does not compare the caller's role rank against the requested role in the…
- CVE-2026-88862 CVSS 8.7 high Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id header…
- CVE-2026-88861 CVSS 8.7 high Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication)…
- CVE-2026-88860 CVSS 9.3 critical Capgo fails to clean up channel permission overrides when a user's last organization role binding is deleted, leaving stale overrides…