Capgo是CAPGO公司的一个专为CapacitorJS开发者打造的移动应用开发和更新平台。 Capgo 12.128.2之前版本存在授权问题漏洞,该漏洞源于accept_invitation端点验证不当,在强制进行验证码验证之前创建用户账户,可能导致攻击者绕过验证码保护,通过发送带有无效验证码令牌的POST请求创建不需要的账户并消耗邀请链接。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56305 | 8.3 HIGH | Capgo - Authentication Bypass in Password Change via Missing Current Password Validation |
| CVE-2026-56279 | 7.5 HIGH | Capgo - Information Disclosure via get_orgs_v7 RPC Endpoint |
| CVE-2026-56335 | 6.5 MEDIUM | Capgo - Channel Configuration Mutation via Write-Scoped API Keys |
| CVE-2026-56329 | 6.4 MEDIUM | Capgo - Cross-Tenant Preview Namespace Collision via Non-Bijective Underscore Decoding |
| CVE-2026-56309 | 5.4 MEDIUM | Capgo - Plan Bypass via Unrestricted Attachment Upload Endpoint |
No comments yet