Capgo是CAPGO公司的一个专为CapacitorJS开发者打造的移动应用开发和更新平台。 Capgo 12.128.2之前版本存在权限许可和访问控制问题漏洞,该漏洞源于不变性触发器中存在空认证检查,导致授权绕过,具有写权限的API密钥可以通过PostgREST修改受保护的通道配置字段,可修改public、allow_emulator等敏感通道属性。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56305 | 8.3 HIGH | Capgo - Authentication Bypass in Password Change via Missing Current Password Validation |
| CVE-2026-56279 | 7.5 HIGH | Capgo - Information Disclosure via get_orgs_v7 RPC Endpoint |
| CVE-2026-56312 | 6.5 MEDIUM | Capgo - Account Creation Before CAPTCHA Validation in accept_invitation Endpoint |
| CVE-2026-56329 | 6.4 MEDIUM | Capgo - Cross-Tenant Preview Namespace Collision via Non-Bijective Underscore Decoding |
| CVE-2026-56309 | 5.4 MEDIUM | Capgo - Plan Bypass via Unrestricted Attachment Upload Endpoint |
No comments yet