Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

capgo — Vulnerabilities & Security Advisories 83

Browse all 83 CVE security advisories affecting capgo. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates security vulnerabilities associated with the Capgo vendor, focusing on weaknesses classified under the Common Weakness Enumeration (CWE) standard. It compiles a comprehensive list of known security issues, tracking data from early reports through the most recent advisories published by the vendor. The content covers various risk levels and software components, ensuring a holistic view of the security posture. Users can utilize this resource to track a vendor's advisories over time, observing how quickly issues are acknowledged and resolved. The page allows security professionals and developers to understand a specific weakness class as it applies to Capgo’s ecosystem, identifying patterns in recurring flaws or specific architectural risks. Additionally, individuals can look up a product's vulnerability history to assess the long-term stability and maintenance quality of the software. By centralizing this information, the page serves as a critical reference for risk assessment, helping stakeholders make informed decisions about software procurement, patching priorities, and compatibility checks. This structured approach eliminates the need to scour multiple sources for disjointed data, providing a single point of truth for Capgo-related security concerns.

Top products by capgo: Capgo cli
CVE IDTitleCVSSSeverityPublished
CVE-2026-56336 Capgo - Information Disclosure via Unauthenticated SSO check-domain Endpoint — CapgoCWE-200 5.3 Medium2026-07-12
CVE-2026-56313 Capgo - Cross-Organization Account Disruption via SSO Prelink Endpoint — CapgoCWE-285 8.1 High2026-07-12
CVE-2026-56308 Capgo - Insufficient Authentication in Email Change Endpoint — CapgoCWE-640 7.3 High2026-07-12
CVE-2026-56281 Capgo - SQL Injection via Unvalidated limit Parameter in Admin Stats Endpoint — CapgoCWE-89 3.8 Low2026-07-12
CVE-2026-56252 Capgo - Scope Isolation Failure in Webhook Test Endpoint — CapgoCWE-863 5.4 Medium2026-07-12
CVE-2026-56241 Capgo - RBAC Demotion Privilege Retention via Stale org_users.user_right — CapgoCWE-285 8.3 High2026-07-12
CVE-2026-56238 Capgo - Unauthenticated Information Disclosure via PostgREST global_stats Endpoint — CapgoCWE-200 7.5 High2026-07-12
CVE-2026-56303 Capgo - Unauthenticated API Key Metadata Disclosure via SECURITY DEFINER RPC Function — CapgoCWE-200 7.5 High2026-07-11
CVE-2026-56240 Capgo - Billing Authorization Bypass via Exhausted Usage Credits — CapgoCWE-285 4.3 Medium2026-07-11
CVE-2026-56335 Capgo - Channel Configuration Mutation via Write-Scoped API Keys — CapgoCWE-284 6.5 Medium2026-07-10
CVE-2026-56312 Capgo - Account Creation Before CAPTCHA Validation in accept_invitation Endpoint — CapgoCWE-287 6.5 Medium2026-07-10
CVE-2026-56329 Capgo - Cross-Tenant Preview Namespace Collision via Non-Bijective Underscore Decoding — CapgoCWE-436 6.4 Medium2026-07-10
CVE-2026-56309 Capgo - Plan Bypass via Unrestricted Attachment Upload Endpoint — CapgoCWE-770 5.4 Medium2026-07-10
CVE-2026-56305 Capgo - Authentication Bypass in Password Change via Missing Current Password Validation — CapgoCWE-620 8.3 High2026-07-10
CVE-2026-56279 Capgo - Information Disclosure via get_orgs_v7 RPC Endpoint — CapgoCWE-862 7.5 High2026-07-10
CVE-2026-56298 Capgo - EXIF Metadata Exposure in App Information Image Upload — CapgoCWE-200 4.3 Medium2026-07-08
CVE-2026-56293 Capgo - Stale Cross-Organization Authorization via Incomplete deploy_history Update in transfer_app() — CapgoCWE-285 5.4 Medium2026-07-08
CVE-2026-56283 Capgo - HTML Injection Leading to Open Redirection in Organization Settings — CapgoCWE-79 5.4 Medium2026-07-08
CVE-2026-56250 Capgo - Arbitrary R2 Object Deletion via Mutable r2_path in app_versions — CapgoCWE-862 7.5 High2026-07-08
CVE-2026-56246 Capgo - Cross-Organization Authorization Bypass via Scoped API Key Privilege Inheritance — CapgoCWE-285 8.1 High2026-07-08
CVE-2026-56220 Capgo - Unauthorized Manifest Insertion via Read-Only Org Member — CapgoCWE-863 6.5 Medium2026-07-08
CVE-2026-56217 Capgo - Encrypted Bundle Policy Bypass via Direct PostgREST Update — CapgoCWE-284 4.3 Medium2026-07-08
CVE-2026-56334 Capgo - Missing UPDATE RLS Policy for Build Status Persistence — CapgoCWE-284 4.3 Medium2026-06-30
CVE-2026-56331 Capgo - Improper Error Handling in Accept Invitation Endpoint via Invalid Magic String — CapgoCWE-209 5.3 Medium2026-06-30
CVE-2026-56333 Capgo - Server-Side Validation Bypass via Direct Browser-Side Organization Security Settings Updates — CapgoCWE-20 4.3 Medium2026-06-30
CVE-2026-56328 Capgo - Integrity Issue in Release Routing via Multiple Public Channels — CapgoCWE-670 6.5 Medium2026-06-30
CVE-2026-56327 Capgo - Unauthenticated Organization Existence Oracle via public.invite_user_to_org RPC — CapgoCWE-203 5.3 Medium2026-06-30
CVE-2026-56320 Capgo - Org/App Scope Mismatch in Device Creation Endpoint — CapgoCWE-285 7.1 High2026-06-30
CVE-2026-56318 Capgo - Information Disclosure via /private/validate_password_compliance Endpoint — CapgoCWE-200 5.3 Medium2026-06-30
CVE-2026-56286 Capgo - Account Deletion Without Password Confirmation — CapgoCWE-306 8.1 High2026-06-30

This page lists every published CVE security advisory associated with capgo. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.