Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

capgo — Vulnerabilities & Security Advisories 99

All 99 CVE vulnerabilities found in capgo, with AI-generated Chinese analysis, references, and POCs.

The capgo vulnerability aggregation page tracks Common Weakness Enumerations (CWEs) associated with the capgo product developed by the capgo vendor. This page collects data on identified security flaws, ranging from critical remote code execution risks to less severe information disclosure issues, covering a historical time range from the first reported discovery in 2022 through current updates in 2024. Here, you can discover detailed records of vendor advisories to track how the capgo team responds to emerging threats, understand the specific characteristics of each weakness class affecting the software, and look up a comprehensive vulnerability history to assess the long-term security posture of the product over time. The data includes severity ratings, publication dates, and references to external databases, providing a centralized resource for security researchers, developers, and system administrators. By analyzing these aggregated entries, users can identify patterns in defect types, evaluate the effectiveness of past patches, and prioritize remediation efforts based on the specific risk profile of capgo installations. This resource serves as a factual record without promotional content, ensuring that all information presented is strictly technical and aimed at facilitating informed decision-making regarding software maintenance and risk management strategies for environments utilizing this specific product line.

Vendor: Cap-go

CVE IDTitleCVSSSeverityPublished
CVE-2026-56324 Capgo - Rate Limit Bypass via User-Controlled device_id Parameter CWE-770 8.2 High2026-06-22
CVE-2026-56321 Capgo - Missing Authentication Middleware on GET /private/role_bindings Endpoint CWE-306 5.3 Medium2026-06-22
CVE-2026-56311 Capgo - Unauthenticated Cross-Tenant Disclosure via get_current_plan_max_org RPC CWE-285 5.3 Medium2026-06-22
CVE-2026-56314 Capgo - Deleted Bundle Selection via Missing Deletion Filter in /updates Endpoint CWE-672 7.1 High2026-06-22
CVE-2026-56306 Capgo - Subkey Enforcement Bypass via x-limited-key-id Header Parsing CWE-20 6.4 Medium2026-06-22
CVE-2026-56280 Cap-go - Privilege Inversion in Build Log Stream via SSE Disconnect CWE-862 7.1 High2026-06-22
CVE-2026-56255 Capgo - Denial of Service via Unlimited Demo App Creation CWE-770 4.3 Medium2026-06-22
CVE-2026-56221 Cap-go - SQL Injection in Cloudflare Analytics Engine Queries via cloudflare.ts CWE-89 6.5 Medium2026-06-22
CVE-2026-56299 Capgo - Denial of Service via Unauthenticated OPTIONS Request to /build/upload Endpoint CWE-306 5.3 Medium2026-06-21
CVE-2026-56316 Cap-go - Job Existence Oracle via Unauthenticated OPTIONS /build/upload/:jobId/* CWE-203 5.3 Medium2026-06-21
CVE-2026-56253 Capgo - Unauthenticated Organization Member Email Disclosure via get_org_members RPC CWE-284 7.5 High2026-06-21
CVE-2026-56251 Capgo - Privilege Escalation via Broken Row Level Security in org_users CWE-266 6.5 Medium2026-06-21
CVE-2026-56242 Capgo - Unauthenticated API Key Validity Oracle and User Identity Disclosure via get_identity_apikey_only RPC CWE-200 7.5 High2026-06-21
CVE-2026-56239 Capgo - Privilege Escalation via SECURITY DEFINER Function apply_usage_overage CWE-269 7.6 High2026-06-21
CVE-2026-56229 Capgo - Cross-App Build Job Access via app_id/job_id Mismatch in /build/status and /build/logs CWE-639 6.5 Medium2026-06-21
CVE-2026-56332 Capgo - Open Redirect via confirmation_url Parameter CWE-601 4.7 Medium2026-06-20
CVE-2026-56330 Capgo - Open Redirect via Unvalidated Stripe Billing URLs CWE-601 3.5 Low2026-06-20
CVE-2026-56319 Capgo - App Existence Oracle via GET /statistics/app/:app_id CWE-203 4.3 Medium2026-06-20
CVE-2026-56307 Cap-go - Broken Cursor Pagination in /private/devices Endpoint CWE-670 4.3 Medium2026-06-20
CVE-2026-56295 Capgo - Policy Enforcement Bypass in Webhook Management Endpoints via Non-Expiring API Keys CWE-285 6.3 Medium2026-06-20
CVE-2026-56282 Capgo - Information Disclosure via Unauthenticated /replication Endpoint CWE-200 5.3 Medium2026-06-20
CVE-2026-56235 Capgo - Unauthenticated Cross-Tenant Metrics Disclosure via RPC Functions CWE-200 5.3 Medium2026-06-20
CVE-2026-56228 Capgo - Denial of Service via Improper Password Policy Length Validation CWE-20 4.9 Medium2026-06-20
CVE-2026-56227 Capgo - Server-Side Request Forgery via Webhook URL Validation CWE-918 5.4 Medium2026-06-20
CVE-2026-56218 Capgo - EXIF Metadata Exposure via Image Upload CWE-200 5.3 Medium2026-06-20
CVE-2026-56325 Capgo - App ID Confusion via ILIKE Wildcard in Preview Subdomain Lookup CWE-20 3.1 Low2026-06-20
CVE-2026-56216 Capgo - Scope Escalation via API Key Creation in /functions/v1/apikey CWE-269 8.8 High2026-06-20
CVE-2026-56214 Capgo - Unauthenticated Organization Enumeration and Billing Status Disclosure via Supabase RPC CWE-200 7.5 High2026-06-20
CVE-2026-56215 Capgo - Account Merge via Poisoned public.users.email in SSO Provisioning CWE-639 8.3 High2026-06-20
CVE-2026-56213 Capgo - Unauthenticated Cross-Tenant Metrics Poisoning via upsert_version_meta RPC CWE-862 5.3 Medium2026-06-20

All 99 known CVE vulnerabilities affecting capgo with full Chinese analysis, references, and POCs where available.