Capgo是CAPGO公司的一个专为CapacitorJS开发者打造的移动应用开发和更新平台。 Capgo 12.128.2之前版本存在资源管理错误漏洞,该漏洞源于channel_self端点存在速率限制绕过问题,允许攻击者通过轮换用户控制的device_id参数,每秒发送多个请求来淹没channel_devices表,导致数据库资源耗尽。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-56323 | 7.5 HIGH | Capgo - Unauthenticated Channel Enumeration and App Oracle via GET /channel_self |
| CVE-2026-56314 | 7.1 HIGH | Capgo - Deleted Bundle Selection via Missing Deletion Filter in /updates Endpoint |
| CVE-2026-56306 | 6.4 MEDIUM | Capgo - Subkey Enforcement Bypass via x-limited-key-id Header Parsing |
| CVE-2026-56311 | 5.3 MEDIUM | Capgo - Unauthenticated Cross-Tenant Disclosure via get_current_plan_max_org RPC |
| CVE-2026-56321 | 5.3 MEDIUM | Capgo - Missing Authentication Middleware on GET /private/role_bindings Endpoint |
| CVE-2026-56255 | 4.3 MEDIUM | Capgo - Denial of Service via Unlimited Demo App Creation |
No comments yet