Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

capgo — Vulnerabilities & Security Advisories 58

All 58 CVE vulnerabilities found in capgo, with AI-generated Chinese analysis, references, and POCs.

The vulnerability aggregation page for Product capgo provides a comprehensive overview of known security weaknesses associated with this software vendor and its specific product line. This resource is designed to help security professionals, developers, and compliance officers monitor the security posture of capgo by centralizing vulnerability data from multiple authoritative sources. The page collects a wide variety of vulnerability types, including but not limited to remote code execution flaws, cross-site scripting issues, authentication bypasses, and privilege escalation vulnerabilities. It covers historical data spanning several years, allowing users to analyze trends and assess the long-term security maturity of the product. By visiting this page, you can track a vendor's advisories to stay updated on newly disclosed issues and patched vulnerabilities. You can also understand a weakness class by examining common patterns and attack vectors specific to capgo's architecture. Additionally, the page enables you to look up a product's vulnerability history to review past incidents, understand remediation efforts, and evaluate risk exposure over time. This consolidated view facilitates more efficient risk management and informed decision-making regarding software procurement, updates, and security audits. All information is presented in a structured format to ensure clarity and ease of use, supporting proactive security hygiene without requiring users to navigate multiple external databases or fragmented reports.

Vendor: Cap-go

CVE IDTitleCVSSSeverityPublished
CVE-2026-56337 Capgo - Information Disclosure via Unauthenticated RPC Function exist_app_v2 CWE-200 5.3 Medium2026-06-24
CVE-2026-56338 Capgo - Denial of Service in 2FA Email Verification via /auth/v1/otp Endpoint CWE-703 5.3 Medium2026-06-24
CVE-2026-56310 Cap-go - Authorization Bypass in Organization Members Endpoint via API Key Scope Bypass CWE-285 4.3 Medium2026-06-24
CVE-2026-56302 Capgo - Unsecured Supabase Images Bucket via Missing Row Level Security CWE-284 6.5 Medium2026-06-24
CVE-2026-56257 Capgo - Authorization Bypass in App Ownership Transfer via Direct PostgREST Update CWE-284 7.1 High2026-06-24
CVE-2026-56256 Capgo - Two-Factor Authentication Bypass via Organization Management API CWE-602 7.1 High2026-06-24
CVE-2026-56245 Supabase Capgo - Unauthenticated Cross-Tenant Build-Time Accounting Poisoning via record_build_time RPC CWE-269 8.2 High2026-06-24
CVE-2026-56244 Capgo - Webhook Signing Secret Disclosure via Non-Admin API Key CWE-200 7.1 High2026-06-24
CVE-2026-56237 Capgo - Unauthenticated API Key Generation via Client-Side Parameter Manipulation CWE-287 9.1 Critical2026-06-24
CVE-2026-56231 Capgo - Broken Object Level Authorization in Build Job Control via jobId Parameter CWE-285 7.6 High2026-06-24
CVE-2026-56232 Capgo - Subkey Scope Bypass in middlewareKey via x-limited-key-id Header CWE-863 8.8 High2026-06-24
CVE-2026-56223 Capgo - Account Takeover via Cross-Domain SSO Email Assertion in provision-user CWE-287 8.7 High2026-06-24
CVE-2026-56322 Capgo - Information Disclosure via Unauthenticated /updates defaultChannel Parameter CWE-200 7.5 High2026-06-23
CVE-2026-56248 Capgo - Unauthenticated Denial-of-Service via audit_logs RLS Policy CWE-400 7.5 High2026-06-23
CVE-2026-56243 Capgo - Hashed API Key Enforcement Bypass via PostgREST/RLS Plane CWE-288 8.1 High2026-06-23
CVE-2026-56225 Capgo - Authorization Bypass in API Key Management via App-Limited Keys CWE-269 8.3 High2026-06-23
CVE-2026-56234 Capgo - Password Spraying via Public-Key Accessible Credential Validation Endpoint CWE-307 5.3 Medium2026-06-23
CVE-2026-56222 Capgo - Cross-Organization App Takeover via Mismatched org_id and app_id in /private/role_bindings CWE-639 7.2 High2026-06-23
CVE-2026-56324 Capgo - Rate Limit Bypass via User-Controlled device_id Parameter CWE-770 8.2 High2026-06-22
CVE-2026-56323 Capgo - Unauthenticated Channel Enumeration and App Oracle via GET /channel_self CWE-200 7.5 High2026-06-22
CVE-2026-56321 Capgo - Missing Authentication Middleware on GET /private/role_bindings Endpoint CWE-306 5.3 Medium2026-06-22
CVE-2026-56311 Capgo - Unauthenticated Cross-Tenant Disclosure via get_current_plan_max_org RPC CWE-285 5.3 Medium2026-06-22
CVE-2026-56314 Capgo - Deleted Bundle Selection via Missing Deletion Filter in /updates Endpoint CWE-672 7.1 High2026-06-22
CVE-2026-56306 Capgo - Subkey Enforcement Bypass via x-limited-key-id Header Parsing CWE-20 6.4 Medium2026-06-22
CVE-2026-56280 Cap-go - Privilege Inversion in Build Log Stream via SSE Disconnect CWE-862 7.1 High2026-06-22
CVE-2026-56255 Capgo - Denial of Service via Unlimited Demo App Creation CWE-770 4.3 Medium2026-06-22
CVE-2026-56221 Cap-go - SQL Injection in Cloudflare Analytics Engine Queries via cloudflare.ts CWE-89 6.5 Medium2026-06-22
CVE-2026-56316 Cap-go - Job Existence Oracle via Unauthenticated OPTIONS /build/upload/:jobId/* CWE-203 5.3 Medium2026-06-21
CVE-2026-56299 Capgo - Denial of Service via Unauthenticated OPTIONS Request to /build/upload Endpoint CWE-306 5.3 Medium2026-06-21
CVE-2026-56253 Capgo - Unauthenticated Organization Member Email Disclosure via get_org_members RPC CWE-284 7.5 High2026-06-21

All 58 known CVE vulnerabilities affecting capgo with full Chinese analysis, references, and POCs where available.