Capgo是CAPGO公司的一个专为CapacitorJS开发者打造的移动应用开发和更新平台。 Capgo 12.128.2之前版本存在信息泄露漏洞,该漏洞源于未经验证的/updates接口在强制执行隐私限制之前解析defaultChannel参数,可能导致攻击者枚举私有频道并泄露版本或配置状态信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-56225 | 8.3 HIGH | Capgo - Authorization Bypass in API Key Management via App-Limited Keys |
| CVE-2026-56243 | 8.1 HIGH | Capgo - Hashed API Key Enforcement Bypass via PostgREST/RLS Plane |
| CVE-2026-56222 | 7.2 HIGH | Capgo - Cross-Organization App Takeover via Mismatched org_id and app_id in /private/role_ |
| CVE-2026-56234 | 5.3 MEDIUM | Capgo - Password Spraying via Public-Key Accessible Credential Validation Endpoint |
No comments yet