Capgo是CAPGO公司的一个专为CapacitorJS开发者打造的移动应用开发和更新平台。 Capgo 12.128.2之前版本存在权限许可和访问控制问题漏洞,该漏洞源于org_users表中行级安全策略失效,可能导致经过身份验证的用户将权限从admin提升至super_admin。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56239 | 7.6 HIGH | Capgo - Privilege Escalation via SECURITY DEFINER Function apply_usage_overage |
| CVE-2026-56242 | 7.5 HIGH | Capgo - Unauthenticated API Key Validity Oracle and User Identity Disclosure via get_ident |
| CVE-2026-56253 | 7.5 HIGH | Capgo - Unauthenticated Organization Member Email Disclosure via get_org_members RPC |
| CVE-2026-56229 | 6.5 MEDIUM | Capgo - Cross-App Build Job Access via app_id/job_id Mismatch in /build/status and /build/ |
| CVE-2026-56236 | 6.1 MEDIUM | Capgo CLI - Arbitrary File Overwrite via Symlink-Following in Local Credential Operations |
| CVE-2026-56299 | 5.3 MEDIUM | Capgo - Denial of Service via Unauthenticated OPTIONS Request to /build/upload Endpoint |
No comments yet