VYPR

@capgo/capgo

by @capgo

Source repositories

CVEs (2)

  • CVE-2026-56299MedJun 21, 2026
    risk 0.35cvss 5.3epss 0.01

    Capgo before 12.128.2 contains an authentication bypass vulnerability in the /build/upload/:jobId/* endpoint that allows unauthenticated attackers to trigger consistent 500 errors. Remote attackers can send OPTIONS requests to bypass authentication middleware and invoke tusProxy…

  • CVE-2026-56307MedJun 20, 2026
    risk 0.28cvss 4.3epss 0.00

    Cap-go before 12.128.12 contains a broken cursor pagination vulnerability in the /private/devices endpoint on the Cloudflare/workerd path that allows authenticated attackers to cause duplicate-page loops and make later rows unreachable. Attackers with app.read_devices access can…