VYPR

Capgo.app

by Cap Go

CVEs (99)

  • CVE-2026-56235MedJun 20, 2026
    risk 0.34cvss 5.3epss 0.00

    Cap-go capgo before 12.128.2 contains an authorization bypass in several Supabase PostgREST RPC functions (get_app_metrics, get_global_metrics, get_total_metrics) that are granted to the anon role without enforcing org membership or permission checks. An unauthenticated attacker…

  • CVE-2026-56218MedJun 20, 2026
    risk 0.34cvss 5.3epss 0.00

    Capgo before 12.128.2 fails to strip EXIF metadata including GPS geolocation data from uploaded images, allowing information disclosure. Attackers can download uploaded images and extract precise latitude and longitude coordinates revealing user physical location at capture time.

  • CVE-2026-56213MedJun 20, 2026
    risk 0.34cvss 5.3epss 0.00

    Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.upsert_version_meta SECURITY DEFINER function exposed via PostgREST RPC, allowing unauthenticated attackers to insert arbitrary rows into version_meta for any app_id. Attackers can exploit this by…

  • CVE-2026-56228MedJun 20, 2026
    risk 0.32cvss 4.9epss 0.00

    Capgo before 12.128.2 fails to enforce a maximum value on the minimum password length field in its password policy configuration. An authenticated organization administrator can set an extremely large numeric value (e.g., billions of characters) as the minimum password length,…

  • CVE-2026-56080MedJun 19, 2026
    risk 0.32cvss 4.9epss 0.01

    Capgo before 12.128.2 contains a flaw in the Enforce Password Policy feature: after a Super Admin enables the policy and successfully changes their password to a compliant one, the backend does not update the password-compliance state. As a result, the backend continues to treat…

  • CVE-2026-56332MedJun 20, 2026
    risk 0.31cvss 4.7epss 0.00

    Capgo before 12.128.2 contains an open redirect vulnerability in the confirm-signup endpoint that allows attackers to redirect users to arbitrary external websites. The confirmation_url parameter is not validated, enabling attackers to craft malicious links for phishing and…

  • CVE-2026-56294MedJun 20, 2026
    risk 0.31cvss 4.8epss 0.00

    capacitor-native-biometric before 12.128.2 contains an authentication bypass vulnerability where the onAuthenticationSucceeded() method fails to validate CryptoObject parameters. Attackers can hook the onAuthenticationSucceeded() function using dynamic instrumentation to bypass…

  • CVE-2026-56255MedJun 22, 2026
    risk 0.28cvss 4.3epss 0.00

    Capgo before 12.128.2 contains a denial of service vulnerability in the POST /app/demo endpoint that allows authenticated users with org write permissions to create unlimited demo applications without rate limiting or quota enforcement. Attackers can repeatedly invoke this…

  • CVE-2026-56319MedJun 20, 2026
    risk 0.28cvss 4.3epss 0.00

    Capgo before 12.128.2 contains an information disclosure vulnerability in the GET /statistics/app/:app_id endpoint that allows app-limited API keys to distinguish existing sibling app IDs through differential error responses. Attackers can enumerate real app IDs outside their…

  • CVE-2026-56307MedJun 20, 2026
    risk 0.28cvss 4.3epss 0.00

    Cap-go before 12.128.12 contains a broken cursor pagination vulnerability in the /private/devices endpoint on the Cloudflare/workerd path that allows authenticated attackers to cause duplicate-page loops and make later rows unreachable. Attackers with app.read_devices access can…

  • CVE-2026-56338MedJun 24, 2026
    risk 0.27cvss 5.3epss 0.00

    Capgo before 12.128.2 contains a denial of service vulnerability in the /auth/v1/otp endpoint that prevents email verification for two-factor authentication due to captcha validation failures. Authenticated users cannot complete 2FA enrollment as the backend consistently returns…

  • CVE-2026-56337MedJun 24, 2026
    risk 0.27cvss 5.3epss 0.00

    Capgo before 12.128.2 contains an information disclosure vulnerability in the public.exist_app_v2 RPC function that allows unauthenticated attackers to enumerate app_ids by calling POST /rest/v1/rpc/exist_app_v2 with arbitrary appid parameters. Remote attackers can exploit this…

  • CVE-2026-56234MedJun 23, 2026
    risk 0.27cvss 5.3epss 0.00

    Capgo before 12.128.2 contains a credential validation vulnerability in the POST /functions/v1/private/validate_password_compliance endpoint that is callable using only the public Supabase key without authentication. The endpoint is CORS-permissive with wildcard origin allowance…

  • CVE-2026-56212LowJun 20, 2026
    risk 0.25cvss 3.8epss 0.00

    Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organization security settings can enable mandatory two-factor authentication for all team members without first enabling 2FA on their own account. The application fails to…

  • CVE-2026-56330LowJun 20, 2026
    risk 0.23cvss 3.5epss 0.00

    Capgo before 12.128.2 contains an open redirect vulnerability in stripe_portal and stripe_checkout endpoints that accept unvalidated callbackUrl, successUrl, and cancelUrl parameters. Authenticated attackers can craft malicious billing URLs to redirect users to…

  • CVE-2026-56310MedJun 24, 2026
    risk 0.21cvss 4.3epss 0.00

    Cap-go before 12.128.2 contains an authorization bypass vulnerability in the GET /organization/members endpoint that allows org-limited API keys to bypass limited_to_orgs restrictions. Attackers with org-limited API keys can read membership data including uid, email, image_url,…

  • CVE-2026-56325LowJun 20, 2026
    risk 0.20cvss 3.1epss 0.00

    Capgo before 12.128.2 uses ILIKE pattern matching instead of exact matching for app_id lookup in the preview subdomain resolver, allowing underscore characters in app_id to act as SQL wildcards. Attackers can create apps with app_ids differing by one character at underscore…

  • CVE-2026-56339HigJul 15, 2026
    risk 0.00cvss 7.5epss 0.00

    Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST SECURITY DEFINER RPC function public.rescind_invitation that allows unauthenticated attackers to enumerate organization existence. The function returns distinct error…

  • CVE-2026-56336MedJul 12, 2026
    risk 0.00cvss 5.3epss 0.00

    Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain endpoint that returns internal org_id and provider_id values. Attackers can enumerate email domains to build mappings of domains to organization UUIDs and SSO…

  • CVE-2026-56313HigJul 12, 2026
    risk 0.00cvss 8.1epss 0.00

    Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that allows enterprise administrators to delete password identities of users in foreign organizations. Attackers with org.update_settings permission and an active SSO…