Capgo是CAPGO公司的一个专为CapacitorJS开发者打造的移动应用开发和更新平台。 Capgo 12.128.2之前版本存在权限许可和访问控制问题漏洞,该漏洞源于public.get_org_members RPC函数存在访问控制不当,可能导致未经身份验证的攻击者使用sb_publishable_*公钥和组织UUID枚举成员并检索敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-56239 | 7.6 HIGH | Capgo - Privilege Escalation via SECURITY DEFINER Function apply_usage_overage |
| CVE-2026-56242 | 7.5 HIGH | Capgo - Unauthenticated API Key Validity Oracle and User Identity Disclosure via get_ident |
| CVE-2026-56229 | 6.5 MEDIUM | Capgo - Cross-App Build Job Access via app_id/job_id Mismatch in /build/status and /build/ |
| CVE-2026-56251 | 6.5 MEDIUM | Capgo - Privilege Escalation via Broken Row Level Security in org_users |
| CVE-2026-56236 | 6.1 MEDIUM | Capgo CLI - Arbitrary File Overwrite via Symlink-Following in Local Credential Operations |
| CVE-2026-56299 | 5.3 MEDIUM | Capgo - Denial of Service via Unauthenticated OPTIONS Request to /build/upload Endpoint |
No comments yet