Capgo是CAPGO公司的一个专为CapacitorJS开发者打造的移动应用开发和更新平台。 Capgo 12.128.2之前版本存在授权问题漏洞,该漏洞源于/build/upload/:jobId/*端点存在认证绕过,可能导致未经验证的攻击者发送OPTIONS请求绕过身份验证中间件并调用tusProxy逻辑,从而触发请求泛洪和拒绝服务攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56239 | 7.6 HIGH | Capgo - Privilege Escalation via SECURITY DEFINER Function apply_usage_overage |
| CVE-2026-56242 | 7.5 HIGH | Capgo - Unauthenticated API Key Validity Oracle and User Identity Disclosure via get_ident |
| CVE-2026-56253 | 7.5 HIGH | Capgo - Unauthenticated Organization Member Email Disclosure via get_org_members RPC |
| CVE-2026-56229 | 6.5 MEDIUM | Capgo - Cross-App Build Job Access via app_id/job_id Mismatch in /build/status and /build/ |
| CVE-2026-56251 | 6.5 MEDIUM | Capgo - Privilege Escalation via Broken Row Level Security in org_users |
| CVE-2026-56236 | 6.1 MEDIUM | Capgo CLI - Arbitrary File Overwrite via Symlink-Following in Local Credential Operations |
No comments yet