Capgo是CAPGO公司的一个专为CapacitorJS开发者打造的移动应用开发和更新平台。 Capgo 12.128.2之前版本存在处理逻辑错误漏洞,该漏洞源于预览主机名解析中双下划线到点的非双射解码导致跨租户预览命名空间冲突,攻击者可注册带下划线的App ID与其他租户的点分隔App ID发生冲突,导致预览路由错误和拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56305 | 8.3 HIGH | Capgo - Authentication Bypass in Password Change via Missing Current Password Validation |
| CVE-2026-56279 | 7.5 HIGH | Capgo - Information Disclosure via get_orgs_v7 RPC Endpoint |
| CVE-2026-56312 | 6.5 MEDIUM | Capgo - Account Creation Before CAPTCHA Validation in accept_invitation Endpoint |
| CVE-2026-56335 | 6.5 MEDIUM | Capgo - Channel Configuration Mutation via Write-Scoped API Keys |
| CVE-2026-56309 | 5.4 MEDIUM | Capgo - Plan Bypass via Unrestricted Attachment Upload Endpoint |
No comments yet