以下是这段漏洞描述的中文翻译: CapGo 应用(npm 包 )在版本 12.207.1 及之前的版本中,在 的 函数中,未将调用者的角色等级与所请求的角色进行比对。 端点在邀请 时仅要求 权限,因此,仅持有 权限的已认证用户(例如 )可以将外部用户邀请为 或 。当被邀请的账户通过 接受邀请时, 会使用 Supabase 服务角色密钥创建角色绑定,从而绕过了 和 数据库触发器。这导致权限提升,使得攻击者能够获得对组织中应用、频道、成员和账单的完全管理控制。该问题已通过拉取请求 #3096 得到修复,该修改在允许提升
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88864 | 9.1 CRITICAL | Capgo SSO Provider Authentication Bypass via PostgREST Direct Write |
| CVE-2026-88862 | 8.8 HIGH | Capgo API Key Manager Authentication Bypass via x-limited-key-id |
| CVE-2026-88861 | 8.3 HIGH | Capgo AAL1 Session MFA Bypass via Direct RBAC Authorization |
| CVE-2026-88860 | 6.3 MEDIUM | Capgo Authorization Bypass via Stale Channel Permission Overrides |
No comments yet