Capgo是CAPGO公司的一个专为CapacitorJS开发者打造的移动应用开发和更新平台。 Capgo 12.128.2之前版本存在信息泄露漏洞,该漏洞源于未认证的/private/sso/check-domain端点返回内部org_id和provider_id值,导致信息泄露,攻击者可枚举电子邮件域以建立域与组织UUID和SSO提供程序标识符的映射,从而对Capgo租户进行侦察。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56241 | 8.3 HIGH | Capgo - RBAC Demotion Privilege Retention via Stale org_users.user_right |
| CVE-2026-56313 | 8.1 HIGH | Capgo - Cross-Organization Account Disruption via SSO Prelink Endpoint |
| CVE-2026-56238 | 7.5 HIGH | Capgo - Unauthenticated Information Disclosure via PostgREST global_stats Endpoint |
| CVE-2026-56308 | 7.3 HIGH | Capgo - Insufficient Authentication in Email Change Endpoint |
| CVE-2026-56252 | 5.4 MEDIUM | Capgo - Scope Isolation Failure in Webhook Test Endpoint |
| CVE-2026-56281 | 3.8 LOW | Capgo - SQL Injection via Unvalidated limit Parameter in Admin Stats Endpoint |
No comments yet