Capgo(Cap-go/capgo.app)存在一个身份验证绕过漏洞,该漏洞影响所有版本(在发布时没有已修复的版本)。Edge 授权路径允许仅通过密码认证的 Supabase AAL1(Authentication Assurance Level 1)会话行使特权 RBAC 权限,即使该账户拥有已验证的多因素认证(MFA)因子但该因子未被当前会话使用。具体来说,Edge JWT 中间件(位于 中的 )接受 JWT 令牌时,未验证其认证保障级别(assurance level);而直接的 RBAC 路径(位于 中的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88864 | 9.1 CRITICAL | Capgo SSO Provider Authentication Bypass via PostgREST Direct Write |
| CVE-2026-88862 | 8.8 HIGH | Capgo API Key Manager Authentication Bypass via x-limited-key-id |
| CVE-2026-88863 | 8.1 HIGH | capgo.app through 12.207.1 Privilege Escalation via invite_new_user_to_org |
| CVE-2026-88860 | 6.3 MEDIUM | Capgo Authorization Bypass via Stale Channel Permission Overrides |
No comments yet