Capgo是CAPGO公司的一个专为CapacitorJS开发者打造的移动应用开发和更新平台。 Capgo 12.128.2之前版本存在授权问题漏洞,该漏洞源于PostgREST/RLS平面接受通过capgkey标头发送的明文API密钥,导致安全控制绕过,攻击者可绕过组织级别的哈希密钥强制验证,直接访问受保护资源。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-56225 | 8.3 HIGH | Capgo - Authorization Bypass in API Key Management via App-Limited Keys |
| CVE-2026-56322 | 7.5 HIGH | Capgo - Information Disclosure via Unauthenticated /updates defaultChannel Parameter |
| CVE-2026-56222 | 7.2 HIGH | Capgo - Cross-Organization App Takeover via Mismatched org_id and app_id in /private/role_ |
| CVE-2026-56234 | 5.3 MEDIUM | Capgo - Password Spraying via Public-Key Accessible Credential Validation Endpoint |
No comments yet