Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Capgo — Vulnerabilities & Security Advisories 83

Browse all 83 CVE security advisories affecting Capgo. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates security vulnerability data for the vendor Capgo, specifically focusing on software weakness classifications and associated CVE records. It compiles a comprehensive list of identified security flaws affecting Capgo products, covering historical reports from inception through the most recent updates. Users can utilize this resource to track a vendor's advisories, understand a weakness class, or look up a product's vulnerability history. The collection includes various types of security issues ranging from remote code execution and injection flaws to configuration errors and buffer overflows. Each entry is linked to its corresponding Common Vulnerabilities and Exposures identifier for cross-referencing with external databases. The data is organized to facilitate analysis of the frequency and severity of vulnerabilities over time, helping security professionals assess the overall risk posture of Capgo’s software ecosystem. By aggregating these findings in one location, the page aims to provide transparency into the patch management process and the remediation efforts undertaken by the vendor. This approach allows developers and auditors to quickly identify patterns in reported issues and prioritize security reviews based on the most critical and frequently occurring defects. The information serves as a reference for compliance checks and risk assessments within organizations that depend on Capgo solutions.

Top products by Capgo: Capgo cli
CVE ID Title CVSS Severity Published
CVE-2026-56336 Capgo - Information Disclosure via Unauthenticated SSO check-domain Endpoint — Capgo CWE-200 5.3 Medium 2026-07-12
CVE-2026-56313 Capgo - Cross-Organization Account Disruption via SSO Prelink Endpoint — Capgo CWE-285 8.1 High 2026-07-12
CVE-2026-56308 Capgo - Insufficient Authentication in Email Change Endpoint — Capgo CWE-640 7.3 High 2026-07-12
CVE-2026-56281 Capgo - SQL Injection via Unvalidated limit Parameter in Admin Stats Endpoint — Capgo CWE-89 3.8 Low 2026-07-12
CVE-2026-56252 Capgo - Scope Isolation Failure in Webhook Test Endpoint — Capgo CWE-863 5.4 Medium 2026-07-12
CVE-2026-56241 Capgo - RBAC Demotion Privilege Retention via Stale org_users.user_right — Capgo CWE-285 8.3 High 2026-07-12
CVE-2026-56238 Capgo - Unauthenticated Information Disclosure via PostgREST global_stats Endpoint — Capgo CWE-200 7.5 High 2026-07-12
CVE-2026-56303 Capgo - Unauthenticated API Key Metadata Disclosure via SECURITY DEFINER RPC Function — Capgo CWE-200 7.5 High 2026-07-11
CVE-2026-56240 Capgo - Billing Authorization Bypass via Exhausted Usage Credits — Capgo CWE-285 4.3 Medium 2026-07-11
CVE-2026-56335 Capgo - Channel Configuration Mutation via Write-Scoped API Keys — Capgo CWE-284 6.5 Medium 2026-07-10
CVE-2026-56312 Capgo - Account Creation Before CAPTCHA Validation in accept_invitation Endpoint — Capgo CWE-287 6.5 Medium 2026-07-10
CVE-2026-56329 Capgo - Cross-Tenant Preview Namespace Collision via Non-Bijective Underscore Decoding — Capgo CWE-436 6.4 Medium 2026-07-10
CVE-2026-56309 Capgo - Plan Bypass via Unrestricted Attachment Upload Endpoint — Capgo CWE-770 5.4 Medium 2026-07-10
CVE-2026-56305 Capgo - Authentication Bypass in Password Change via Missing Current Password Validation — Capgo CWE-620 8.3 High 2026-07-10
CVE-2026-56279 Capgo - Information Disclosure via get_orgs_v7 RPC Endpoint — Capgo CWE-862 7.5 High 2026-07-10
CVE-2026-56298 Capgo - EXIF Metadata Exposure in App Information Image Upload — Capgo CWE-200 4.3 Medium 2026-07-08
CVE-2026-56293 Capgo - Stale Cross-Organization Authorization via Incomplete deploy_history Update in transfer_app() — Capgo CWE-285 5.4 Medium 2026-07-08
CVE-2026-56283 Capgo - HTML Injection Leading to Open Redirection in Organization Settings — Capgo CWE-79 5.4 Medium 2026-07-08
CVE-2026-56250 Capgo - Arbitrary R2 Object Deletion via Mutable r2_path in app_versions — Capgo CWE-862 7.5 High 2026-07-08
CVE-2026-56246 Capgo - Cross-Organization Authorization Bypass via Scoped API Key Privilege Inheritance — Capgo CWE-285 8.1 High 2026-07-08
CVE-2026-56220 Capgo - Unauthorized Manifest Insertion via Read-Only Org Member — Capgo CWE-863 6.5 Medium 2026-07-08
CVE-2026-56217 Capgo - Encrypted Bundle Policy Bypass via Direct PostgREST Update — Capgo CWE-284 4.3 Medium 2026-07-08
CVE-2026-56334 Capgo - Missing UPDATE RLS Policy for Build Status Persistence — Capgo CWE-284 4.3 Medium 2026-06-30
CVE-2026-56331 Capgo - Improper Error Handling in Accept Invitation Endpoint via Invalid Magic String — Capgo CWE-209 5.3 Medium 2026-06-30
CVE-2026-56333 Capgo - Server-Side Validation Bypass via Direct Browser-Side Organization Security Settings Updates — Capgo CWE-20 4.3 Medium 2026-06-30
CVE-2026-56328 Capgo - Integrity Issue in Release Routing via Multiple Public Channels — Capgo CWE-670 6.5 Medium 2026-06-30
CVE-2026-56327 Capgo - Unauthenticated Organization Existence Oracle via public.invite_user_to_org RPC — Capgo CWE-203 5.3 Medium 2026-06-30
CVE-2026-56320 Capgo - Org/App Scope Mismatch in Device Creation Endpoint — Capgo CWE-285 7.1 High 2026-06-30
CVE-2026-56318 Capgo - Information Disclosure via /private/validate_password_compliance Endpoint — Capgo CWE-200 5.3 Medium 2026-06-30
CVE-2026-56286 Capgo - Account Deletion Without Password Confirmation — Capgo CWE-306 8.1 High 2026-06-30

This page lists every published CVE security advisory associated with Capgo. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.