Capgo是CAPGO公司的一个专为CapacitorJS开发者打造的移动应用开发和更新平台。 Capgo 12.128.2之前版本存在权限许可和访问控制问题漏洞,该漏洞源于公钥API管理处理程序存在授权绕过问题,可能导致应用作用域密钥枚举、更新和删除相同账户内其他API密钥,从而篡改账户级凭据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-56243 | 8.1 HIGH | Capgo - Hashed API Key Enforcement Bypass via PostgREST/RLS Plane |
| CVE-2026-56322 | 7.5 HIGH | Capgo - Information Disclosure via Unauthenticated /updates defaultChannel Parameter |
| CVE-2026-56222 | 7.2 HIGH | Capgo - Cross-Organization App Takeover via Mismatched org_id and app_id in /private/role_ |
| CVE-2026-56234 | 5.3 MEDIUM | Capgo - Password Spraying via Public-Key Accessible Credential Validation Endpoint |
No comments yet