Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Capgo — Vulnerabilities & Security Advisories 83

Browse all 83 CVE security advisories affecting Capgo. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates security vulnerabilities associated with the Capgo vendor, focusing on weaknesses classified under the Common Weakness Enumeration (CWE) standard. It compiles a comprehensive list of known security issues, tracking data from early reports through the most recent advisories published by the vendor. The content covers various risk levels and software components, ensuring a holistic view of the security posture. Users can utilize this resource to track a vendor's advisories over time, observing how quickly issues are acknowledged and resolved. The page allows security professionals and developers to understand a specific weakness class as it applies to Capgo’s ecosystem, identifying patterns in recurring flaws or specific architectural risks. Additionally, individuals can look up a product's vulnerability history to assess the long-term stability and maintenance quality of the software. By centralizing this information, the page serves as a critical reference for risk assessment, helping stakeholders make informed decisions about software procurement, patching priorities, and compatibility checks. This structured approach eliminates the need to scour multiple sources for disjointed data, providing a single point of truth for Capgo-related security concerns.

Found 82 results / 83 Clear Filters
Top products by Capgo: Capgo cli
CVE ID Title CVSS Severity Published
CVE-2026-56300 Capgo - Unauthenticated API Key Validity and Permission Oracle via RPC Functions — Capgo CWE-200 7.5 High 2026-06-30
CVE-2026-56249 Capgo - Unauthorized Channel Overwrite and Ownership Takeover via POST /channel Name Collision — Capgo CWE-285 7.6 High 2026-06-30
CVE-2026-56247 Capgo - Privilege Escalation via Cross-Scope RBAC Role Assignment — Capgo CWE-266 8.8 High 2026-06-30
CVE-2026-56233 Capgo - SSRF and Privilege Escalation via Path Traversal in Builder Upload Proxy — Capgo CWE-22 8.3 High 2026-06-30
CVE-2026-56230 Capgo - Broken Object Level Authorization via x-limited-key-id Header — Capgo CWE-639 8.8 High 2026-06-30
CVE-2026-56224 Capgo - Login CSRF and Session Fixation via URL Query Parameters — Capgo CWE-384 5.4 Medium 2026-06-30
CVE-2026-56219 Capgo - Unauthenticated RBAC Bindings and Email Disclosure via get_org_user_access_rbac NULL-auth Bypass — Capgo CWE-287 7.5 High 2026-06-30
CVE-2026-56338 Capgo - Denial of Service in 2FA Email Verification via /auth/v1/otp Endpoint — Capgo CWE-703 5.3 Medium 2026-06-24
CVE-2026-56337 Capgo - Information Disclosure via Unauthenticated RPC Function exist_app_v2 — Capgo CWE-200 5.3 Medium 2026-06-24
CVE-2026-56302 Capgo - Unsecured Supabase Images Bucket via Missing Row Level Security — Capgo CWE-284 6.5 Medium 2026-06-24
CVE-2026-56257 Capgo - Authorization Bypass in App Ownership Transfer via Direct PostgREST Update — Capgo CWE-284 7.1 High 2026-06-24
CVE-2026-56256 Capgo - Two-Factor Authentication Bypass via Organization Management API — Capgo CWE-602 7.1 High 2026-06-24
CVE-2026-56244 Capgo - Webhook Signing Secret Disclosure via Non-Admin API Key — Capgo CWE-200 7.1 High 2026-06-24
CVE-2026-56237 Capgo - Unauthenticated API Key Generation via Client-Side Parameter Manipulation — Capgo CWE-287 9.1 Critical 2026-06-24
CVE-2026-56231 Capgo - Broken Object Level Authorization in Build Job Control via jobId Parameter — Capgo CWE-285 7.6 High 2026-06-24
CVE-2026-56232 Capgo - Subkey Scope Bypass in middlewareKey via x-limited-key-id Header — Capgo CWE-863 8.8 High 2026-06-24
CVE-2026-56223 Capgo - Account Takeover via Cross-Domain SSO Email Assertion in provision-user — Capgo CWE-287 8.7 High 2026-06-24
CVE-2026-56322 Capgo - Information Disclosure via Unauthenticated /updates defaultChannel Parameter — Capgo CWE-200 7.5 High 2026-06-23
CVE-2026-56243 Capgo - Hashed API Key Enforcement Bypass via PostgREST/RLS Plane — Capgo CWE-288 8.1 High 2026-06-23
CVE-2026-56234 Capgo - Password Spraying via Public-Key Accessible Credential Validation Endpoint — Capgo CWE-307 5.3 Medium 2026-06-23
CVE-2026-56225 Capgo - Authorization Bypass in API Key Management via App-Limited Keys — Capgo CWE-269 8.3 High 2026-06-23
CVE-2026-56222 Capgo - Cross-Organization App Takeover via Mismatched org_id and app_id in /private/role_bindings — Capgo CWE-639 7.2 High 2026-06-23
CVE-2026-56323 Capgo - Unauthenticated Channel Enumeration and App Oracle via GET /channel_self — Capgo CWE-200 7.5 High 2026-06-22
CVE-2026-56324 Capgo - Rate Limit Bypass via User-Controlled device_id Parameter — Capgo CWE-770 8.2 High 2026-06-22
CVE-2026-56321 Capgo - Missing Authentication Middleware on GET /private/role_bindings Endpoint — Capgo CWE-306 5.3 Medium 2026-06-22
CVE-2026-56311 Capgo - Unauthenticated Cross-Tenant Disclosure via get_current_plan_max_org RPC — Capgo CWE-285 5.3 Medium 2026-06-22
CVE-2026-56314 Capgo - Deleted Bundle Selection via Missing Deletion Filter in /updates Endpoint — Capgo CWE-672 7.1 High 2026-06-22
CVE-2026-56306 Capgo - Subkey Enforcement Bypass via x-limited-key-id Header Parsing — Capgo CWE-20 6.4 Medium 2026-06-22
CVE-2026-56255 Capgo - Denial of Service via Unlimited Demo App Creation — Capgo CWE-770 4.3 Medium 2026-06-22
CVE-2026-56299 Capgo - Denial of Service via Unauthenticated OPTIONS Request to /build/upload Endpoint — Capgo CWE-306 5.3 Medium 2026-06-21

This page lists every published CVE security advisory associated with Capgo. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.