Unrated severityNVD Advisory· Published Jul 10, 2026· Updated Jul 10, 2026
Capgo - Plan Bypass via Unrestricted Attachment Upload Endpoint
CVE-2026-56309
Description
Capgo before 12.128.2 fails to enforce plan/quota restrictions on the /files/upload/attachments endpoint, allowing plan-blocked apps to create publicly readable R2 objects. Attackers can upload arbitrary attachments using upload-scoped API keys that bypass plan checks, persist outside normal bundle metadata, and survive app deletion, enabling storage and bandwidth abuse.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/Cap-go/capgo/security/advisories/GHSA-q52j-ggvx-cr4vmitrevendor-advisory
- www.vulncheck.com/advisories/capgo-plan-bypass-via-unrestricted-attachment-upload-endpointmitrethird-party-advisory
News mentions
0No linked articles in our index yet.