All 5 CVE vulnerabilities found in capgo.app, with AI-generated Chinese analysis, references, and POCs.
Vendor: Cap-go
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-88864 | Capgo SSO Provider Authentication Bypass via PostgREST Direct Write CWE-284 | 9.1 | Critical | 2026-09-10 |
| CVE-2026-88863 | capgo.app through 12.207.1 Privilege Escalation via invite_new_user_to_org CWE-269 | 8.1 | High | 2026-09-10 |
| CVE-2026-88862 | Capgo API Key Manager Authentication Bypass via x-limited-key-id CWE-863 | 8.8 | High | 2026-09-10 |
| CVE-2026-88860 | Capgo Authorization Bypass via Stale Channel Permission Overrides CWE-863 | 6.3 | Medium | 2026-09-10 |
| CVE-2026-88861 | Capgo AAL1 Session MFA Bypass via Direct RBAC Authorization CWE-288 | 8.3 | High | 2026-09-10 |
All 5 known CVE vulnerabilities affecting capgo.app with full Chinese analysis, references, and POCs where available.