Capgo是CAPGO公司的一个专为CapacitorJS开发者打造的移动应用开发和更新平台。 Capgo 12.128.2之前版本存在授权问题漏洞,该漏洞源于身份验证逻辑缺陷,可能导致攻击者在受害者邮箱验证前注册并控制与其邮箱绑定的账户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-56073 | 9.4 CRITICAL | Cap-go - OTP Bypass via Response Manipulation in Email Verification |
| CVE-2026-56082 | 7.5 HIGH | Capgo - Unauthenticated Cross-Tenant Billing Log Tampering via public.record_build_time RP |
| CVE-2026-56080 | 4.9 MEDIUM | Cap-go - Authentication Logic Flaw in Enforce Password Policy |
No comments yet