Capgo是CAPGO公司的一个专为CapacitorJS开发者打造的移动应用开发和更新平台。 Capgo 12.128.2之前版本存在授权问题漏洞,该漏洞源于在POST /private/role_bindings中未能验证app_id所有权,可能导致具有管理权限的攻击者创建跨组织应用程序的角色绑定,从而实现未授权读取和修改受害者应用程序。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-56225 | 8.3 HIGH | Capgo - Authorization Bypass in API Key Management via App-Limited Keys |
| CVE-2026-56243 | 8.1 HIGH | Capgo - Hashed API Key Enforcement Bypass via PostgREST/RLS Plane |
| CVE-2026-56322 | 7.5 HIGH | Capgo - Information Disclosure via Unauthenticated /updates defaultChannel Parameter |
| CVE-2026-56234 | 5.3 MEDIUM | Capgo - Password Spraying via Public-Key Accessible Credential Validation Endpoint |
No comments yet