Capgo是CAPGO公司的一个专为CapacitorJS开发者打造的移动应用开发和更新平台。 Capgo 12.128.2之前版本存在授权问题漏洞,该漏洞源于在POST /functions/v1/private/validate_password_compliance端点中缺乏身份验证,且CORS允许通配符来源并缺少速率限制,可能导致攻击者执行密码喷洒和凭证填充攻击以破解用户账户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56225 | 8.3 HIGH | Capgo - Authorization Bypass in API Key Management via App-Limited Keys |
| CVE-2026-56243 | 8.1 HIGH | Capgo - Hashed API Key Enforcement Bypass via PostgREST/RLS Plane |
| CVE-2026-56322 | 7.5 HIGH | Capgo - Information Disclosure via Unauthenticated /updates defaultChannel Parameter |
| CVE-2026-56222 | 7.2 HIGH | Capgo - Cross-Organization App Takeover via Mismatched org_id and app_id in /private/role_ |
No comments yet