Capgo是CAPGO公司的一个专为CapacitorJS开发者打造的移动应用开发和更新平台。 Capgo 12.128.2之前版本存在输入验证错误漏洞,该漏洞源于对x-limited-key-id标头的解析存在弱点,可能导致远程攻击者通过提交格式错误值、零值或重复标头来绕过子密钥强制执行,使用主API密钥上下文执行请求。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56324 | 8.2 HIGH | Capgo - Rate Limit Bypass via User-Controlled device_id Parameter |
| CVE-2026-56323 | 7.5 HIGH | Capgo - Unauthenticated Channel Enumeration and App Oracle via GET /channel_self |
| CVE-2026-56314 | 7.1 HIGH | Capgo - Deleted Bundle Selection via Missing Deletion Filter in /updates Endpoint |
| CVE-2026-56311 | 5.3 MEDIUM | Capgo - Unauthenticated Cross-Tenant Disclosure via get_current_plan_max_org RPC |
| CVE-2026-56321 | 5.3 MEDIUM | Capgo - Missing Authentication Middleware on GET /private/role_bindings Endpoint |
| CVE-2026-56255 | 4.3 MEDIUM | Capgo - Denial of Service via Unlimited Demo App Creation |
No comments yet