Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100620— Capgo CLI through 7.98.2 Excessive Permissions via Overpermissioned Play Console Service Account

Quick assessment

Affected
Cap-go @capgo/cli
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Capgo CLI(npm 包 )在 7.98.2 及以下版本中存在一个 Android 初始化流程中的服务账户权限过大的漏洞。在使用 Google OAuth 进行初始化的过程中,CLI 会邀请生成的 Google Play 服务账户,并赋予其整个 Play Console 账户范围内的 权限(通过 Android Publisher API 的 User 创建请求中的 参数传递)。然而,用户可见的流程却声称该服务账户仅被邀请至一个已确认的特定应用,并且仅具有发布权限。因此,任何获取到所生成服务账户密钥(即 )的

CVSS 3.8 · Low EPSS 0.25% · P15
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100620

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Capgo CLI through 7.98.2 Excessive Permissions via Overpermissioned Play Console Service Account
Source: CVE Program / CVE List V5
Vulnerability Description
Capgo CLI (npm package @capgo/cli) through 7.98.2 is affected by an over-permissioned service account in its Android onboarding flow. When onboarding via Google OAuth, the CLI invites the generated Google Play service account with the account-wide Play Console permission CAN_MANAGE_DRAFT_APPS_GLOBAL (passed as developerAccountPermissions in the Android Publisher API User create request), even though the user-facing flow states the service account is invited into a single confirmed app with release-only permissions. As a result, anyone who obtains the generated service account key (PLAY_CONFIG_JSON) can create, edit, and delete draft apps across the entire Google Play developer account rather than being limited to the selected package. No patched version was available at the time of publication.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
特权管理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Cap-go @capgo/cli 0 ~ 7.98.2 -

II. Public POCs for CVE-2026-100620

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100620

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100620 (1)

Other References for CVE-2026-100620 (1)

Same Patch Batch · Cap-go · 2026-09-26 · 19 CVEs total

CVE-2026-100615 8.8 HIGH Cap-go capgo.app before 12.267.1 Privilege Escalation via API Key Rotation
CVE-2026-100614 8.8 HIGH Capgo before 12.244.1 Cross-Tenant Image Overwrite via Metadata Worker
CVE-2026-100623 8.8 HIGH Capgo Authentication Bypass via Direct PostgREST org_users Table Write
CVE-2026-100617 8.8 HIGH Cap-go capgo.app Authorization Bypass via channel_permission_overrides
CVE-2026-100619 8.8 HIGH Capgo OTA Manifest Poisoning via app_versions.manifest Bypass
CVE-2026-100618 8.5 HIGH Capgo App Icon Update Privilege Escalation via Service-Role Worker
CVE-2026-100627 8.1 HIGH Capgo bundle promotion API channel RBAC deny override bypass
CVE-2026-100622 7.5 HIGH capgo.app through 12.129.0 Cache Restoration of Deleted Bundles
CVE-2026-100612 7.2 HIGH Capgo SSO Provider ID Authentication Bypass via Incomplete Migration
CVE-2026-100625 7.1 HIGH Capgo Build Upload Proxy Authorization Bypass via TUS Resource
CVE-2026-100611 6.5 MEDIUM Capgo apikey_manager Role Privilege Escalation via Incomplete Role Deny-list
CVE-2026-100629 5.5 MEDIUM Capgo backend before 12.127.5 Privilege Escalation via role_bindings PATCH
CVE-2026-100616 5.5 MEDIUM capgo.app Authentication Bypass via PostgREST customer_id Mutation
CVE-2026-100624 5.4 MEDIUM Capgo.app before 12.264.5 Upload Expiry Bypass via build upload
CVE-2026-100613 5.3 MEDIUM capgo.app Authorization Bypass via Stale Channel Permission Overrides
CVE-2026-100626 4.3 MEDIUM capgo through 12.128.2 IDOR via PUT /app icon endpoint
CVE-2026-100621 4.3 MEDIUM capgo.app Content-Lock Bypass via r2-direct Bundle Mutation
CVE-2026-100628 4.3 MEDIUM capgo.app before 12.128.12 Authentication Bypass via apikey

IV. Related Vulnerabilities

V. Comments for CVE-2026-100620

No comments yet


Leave a comment