Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

capgo — Vulnerabilities & Security Advisories 99

All 99 CVE vulnerabilities found in capgo, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for the capgo product, categorized under software development tools and tagged with mobile application security weaknesses. It compiles a comprehensive list of known security flaws affecting capgo, covering historical data from its initial release through the most recent advisories issued by the vendor. This collection includes critical, high, and medium severity issues that impact the integrity, confidentiality, and availability of applications utilizing the capgo platform. Users can discover essential insights by tracking a vendor's advisories to stay informed about emerging risks, understanding a specific weakness class to better grasp the underlying technical mechanisms of the flaws, and looking up a product's vulnerability history to assess long-term security posture. The aggregated data aims to provide developers, security analysts, and product managers with a clear view of the attack surface associated with capgo. By reviewing the consolidated findings, stakeholders can prioritize patching efforts, improve code review processes, and enhance overall application security practices. This resource serves as a central reference point for evaluating the reliability of the capgo library in production environments. It facilitates informed decision-making regarding version upgrades and dependency management. The page focuses on factual reporting and technical analysis rather than promotional content. Readers are encouraged to use the information for defensive purposes and to integrate these findings into their continuous integration and deployment pipelines for robust security assurance.

Vendor: Cap-go

CVE ID Title CVSS Severity Published
CVE-2026-56324 Capgo - Rate Limit Bypass via User-Controlled device_id Parameter CWE-770 8.2 High 2026-06-22
CVE-2026-56321 Capgo - Missing Authentication Middleware on GET /private/role_bindings Endpoint CWE-306 5.3 Medium 2026-06-22
CVE-2026-56311 Capgo - Unauthenticated Cross-Tenant Disclosure via get_current_plan_max_org RPC CWE-285 5.3 Medium 2026-06-22
CVE-2026-56314 Capgo - Deleted Bundle Selection via Missing Deletion Filter in /updates Endpoint CWE-672 7.1 High 2026-06-22
CVE-2026-56306 Capgo - Subkey Enforcement Bypass via x-limited-key-id Header Parsing CWE-20 6.4 Medium 2026-06-22
CVE-2026-56280 Cap-go - Privilege Inversion in Build Log Stream via SSE Disconnect CWE-862 7.1 High 2026-06-22
CVE-2026-56255 Capgo - Denial of Service via Unlimited Demo App Creation CWE-770 4.3 Medium 2026-06-22
CVE-2026-56221 Cap-go - SQL Injection in Cloudflare Analytics Engine Queries via cloudflare.ts CWE-89 6.5 Medium 2026-06-22
CVE-2026-56299 Capgo - Denial of Service via Unauthenticated OPTIONS Request to /build/upload Endpoint CWE-306 5.3 Medium 2026-06-21
CVE-2026-56316 Cap-go - Job Existence Oracle via Unauthenticated OPTIONS /build/upload/:jobId/* CWE-203 5.3 Medium 2026-06-21
CVE-2026-56253 Capgo - Unauthenticated Organization Member Email Disclosure via get_org_members RPC CWE-284 7.5 High 2026-06-21
CVE-2026-56251 Capgo - Privilege Escalation via Broken Row Level Security in org_users CWE-266 6.5 Medium 2026-06-21
CVE-2026-56242 Capgo - Unauthenticated API Key Validity Oracle and User Identity Disclosure via get_identity_apikey_only RPC CWE-200 7.5 High 2026-06-21
CVE-2026-56239 Capgo - Privilege Escalation via SECURITY DEFINER Function apply_usage_overage CWE-269 7.6 High 2026-06-21
CVE-2026-56229 Capgo - Cross-App Build Job Access via app_id/job_id Mismatch in /build/status and /build/logs CWE-639 6.5 Medium 2026-06-21
CVE-2026-56332 Capgo - Open Redirect via confirmation_url Parameter CWE-601 4.7 Medium 2026-06-20
CVE-2026-56330 Capgo - Open Redirect via Unvalidated Stripe Billing URLs CWE-601 3.5 Low 2026-06-20
CVE-2026-56319 Capgo - App Existence Oracle via GET /statistics/app/:app_id CWE-203 4.3 Medium 2026-06-20
CVE-2026-56307 Cap-go - Broken Cursor Pagination in /private/devices Endpoint CWE-670 4.3 Medium 2026-06-20
CVE-2026-56295 Capgo - Policy Enforcement Bypass in Webhook Management Endpoints via Non-Expiring API Keys CWE-285 6.3 Medium 2026-06-20
CVE-2026-56282 Capgo - Information Disclosure via Unauthenticated /replication Endpoint CWE-200 5.3 Medium 2026-06-20
CVE-2026-56235 Capgo - Unauthenticated Cross-Tenant Metrics Disclosure via RPC Functions CWE-200 5.3 Medium 2026-06-20
CVE-2026-56228 Capgo - Denial of Service via Improper Password Policy Length Validation CWE-20 4.9 Medium 2026-06-20
CVE-2026-56227 Capgo - Server-Side Request Forgery via Webhook URL Validation CWE-918 5.4 Medium 2026-06-20
CVE-2026-56218 Capgo - EXIF Metadata Exposure via Image Upload CWE-200 5.3 Medium 2026-06-20
CVE-2026-56325 Capgo - App ID Confusion via ILIKE Wildcard in Preview Subdomain Lookup CWE-20 3.1 Low 2026-06-20
CVE-2026-56216 Capgo - Scope Escalation via API Key Creation in /functions/v1/apikey CWE-269 8.8 High 2026-06-20
CVE-2026-56214 Capgo - Unauthenticated Organization Enumeration and Billing Status Disclosure via Supabase RPC CWE-200 7.5 High 2026-06-20
CVE-2026-56215 Capgo - Account Merge via Poisoned public.users.email in SSO Provisioning CWE-639 8.3 High 2026-06-20
CVE-2026-56213 Capgo - Unauthenticated Cross-Tenant Metrics Poisoning via upsert_version_meta RPC CWE-862 5.3 Medium 2026-06-20

All 99 known CVE vulnerabilities affecting capgo with full Chinese analysis, references, and POCs where available.