Capgo是CAPGO公司的一个专为CapacitorJS开发者打造的移动应用开发和更新平台。 Capgo 12.128.12之前版本存在资源管理错误漏洞,该漏洞源于在/updates解析期间加入频道时未过滤已删除的应用版本,导致已删除的包仍可被选择,攻击者可利用缺失的app_versions.deleted过滤器继续向设备部署已删除的包。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-56324 | 8.2 HIGH | Capgo - Rate Limit Bypass via User-Controlled device_id Parameter |
| CVE-2026-56323 | 7.5 HIGH | Capgo - Unauthenticated Channel Enumeration and App Oracle via GET /channel_self |
| CVE-2026-56306 | 6.4 MEDIUM | Capgo - Subkey Enforcement Bypass via x-limited-key-id Header Parsing |
| CVE-2026-56311 | 5.3 MEDIUM | Capgo - Unauthenticated Cross-Tenant Disclosure via get_current_plan_max_org RPC |
| CVE-2026-56321 | 5.3 MEDIUM | Capgo - Missing Authentication Middleware on GET /private/role_bindings Endpoint |
| CVE-2026-56255 | 4.3 MEDIUM | Capgo - Denial of Service via Unlimited Demo App Creation |
No comments yet