Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Capgo — Vulnerabilities & Security Advisories 83

Browse all 83 CVE security advisories affecting Capgo. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates security vulnerabilities associated with the Capgo vendor, focusing on weaknesses classified under the Common Weakness Enumeration (CWE) standard. It compiles a comprehensive list of known security issues, tracking data from early reports through the most recent advisories published by the vendor. The content covers various risk levels and software components, ensuring a holistic view of the security posture. Users can utilize this resource to track a vendor's advisories over time, observing how quickly issues are acknowledged and resolved. The page allows security professionals and developers to understand a specific weakness class as it applies to Capgo’s ecosystem, identifying patterns in recurring flaws or specific architectural risks. Additionally, individuals can look up a product's vulnerability history to assess the long-term stability and maintenance quality of the software. By centralizing this information, the page serves as a critical reference for risk assessment, helping stakeholders make informed decisions about software procurement, patching priorities, and compatibility checks. This structured approach eliminates the need to scour multiple sources for disjointed data, providing a single point of truth for Capgo-related security concerns.

Found 82 results / 83 Clear Filters
Top products by Capgo: Capgo cli
CVE ID Title CVSS Severity Published
CVE-2026-56336 Capgo - Information Disclosure via Unauthenticated SSO check-domain Endpoint — Capgo CWE-200 5.3 Medium 2026-07-12
CVE-2026-56313 Capgo - Cross-Organization Account Disruption via SSO Prelink Endpoint — Capgo CWE-285 8.1 High 2026-07-12
CVE-2026-56308 Capgo - Insufficient Authentication in Email Change Endpoint — Capgo CWE-640 7.3 High 2026-07-12
CVE-2026-56281 Capgo - SQL Injection via Unvalidated limit Parameter in Admin Stats Endpoint — Capgo CWE-89 3.8 Low 2026-07-12
CVE-2026-56252 Capgo - Scope Isolation Failure in Webhook Test Endpoint — Capgo CWE-863 5.4 Medium 2026-07-12
CVE-2026-56241 Capgo - RBAC Demotion Privilege Retention via Stale org_users.user_right — Capgo CWE-285 8.3 High 2026-07-12
CVE-2026-56238 Capgo - Unauthenticated Information Disclosure via PostgREST global_stats Endpoint — Capgo CWE-200 7.5 High 2026-07-12
CVE-2026-56303 Capgo - Unauthenticated API Key Metadata Disclosure via SECURITY DEFINER RPC Function — Capgo CWE-200 7.5 High 2026-07-11
CVE-2026-56240 Capgo - Billing Authorization Bypass via Exhausted Usage Credits — Capgo CWE-285 4.3 Medium 2026-07-11
CVE-2026-56335 Capgo - Channel Configuration Mutation via Write-Scoped API Keys — Capgo CWE-284 6.5 Medium 2026-07-10
CVE-2026-56312 Capgo - Account Creation Before CAPTCHA Validation in accept_invitation Endpoint — Capgo CWE-287 6.5 Medium 2026-07-10
CVE-2026-56329 Capgo - Cross-Tenant Preview Namespace Collision via Non-Bijective Underscore Decoding — Capgo CWE-436 6.4 Medium 2026-07-10
CVE-2026-56309 Capgo - Plan Bypass via Unrestricted Attachment Upload Endpoint — Capgo CWE-770 5.4 Medium 2026-07-10
CVE-2026-56279 Capgo - Information Disclosure via get_orgs_v7 RPC Endpoint — Capgo CWE-862 7.5 High 2026-07-10
CVE-2026-56305 Capgo - Authentication Bypass in Password Change via Missing Current Password Validation — Capgo CWE-620 8.3 High 2026-07-10
CVE-2026-56298 Capgo - EXIF Metadata Exposure in App Information Image Upload — Capgo CWE-200 4.3 Medium 2026-07-08
CVE-2026-56293 Capgo - Stale Cross-Organization Authorization via Incomplete deploy_history Update in transfer_app() — Capgo CWE-285 5.4 Medium 2026-07-08
CVE-2026-56283 Capgo - HTML Injection Leading to Open Redirection in Organization Settings — Capgo CWE-79 5.4 Medium 2026-07-08
CVE-2026-56250 Capgo - Arbitrary R2 Object Deletion via Mutable r2_path in app_versions — Capgo CWE-862 7.5 High 2026-07-08
CVE-2026-56246 Capgo - Cross-Organization Authorization Bypass via Scoped API Key Privilege Inheritance — Capgo CWE-285 8.1 High 2026-07-08
CVE-2026-56220 Capgo - Unauthorized Manifest Insertion via Read-Only Org Member — Capgo CWE-863 6.5 Medium 2026-07-08
CVE-2026-56217 Capgo - Encrypted Bundle Policy Bypass via Direct PostgREST Update — Capgo CWE-284 4.3 Medium 2026-07-08
CVE-2026-56334 Capgo - Missing UPDATE RLS Policy for Build Status Persistence — Capgo CWE-284 4.3 Medium 2026-06-30
CVE-2026-56331 Capgo - Improper Error Handling in Accept Invitation Endpoint via Invalid Magic String — Capgo CWE-209 5.3 Medium 2026-06-30
CVE-2026-56333 Capgo - Server-Side Validation Bypass via Direct Browser-Side Organization Security Settings Updates — Capgo CWE-20 4.3 Medium 2026-06-30
CVE-2026-56328 Capgo - Integrity Issue in Release Routing via Multiple Public Channels — Capgo CWE-670 6.5 Medium 2026-06-30
CVE-2026-56320 Capgo - Org/App Scope Mismatch in Device Creation Endpoint — Capgo CWE-285 7.1 High 2026-06-30
CVE-2026-56327 Capgo - Unauthenticated Organization Existence Oracle via public.invite_user_to_org RPC — Capgo CWE-203 5.3 Medium 2026-06-30
CVE-2026-56318 Capgo - Information Disclosure via /private/validate_password_compliance Endpoint — Capgo CWE-200 5.3 Medium 2026-06-30
CVE-2026-56286 Capgo - Account Deletion Without Password Confirmation — Capgo CWE-306 8.1 High 2026-06-30

This page lists every published CVE security advisory associated with Capgo. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.