VYPR

Capgo.app

by Cap Go

Source repositories

CVEs (104)

  • CVE-2026-56332MedJun 20, 2026
    risk 0.24cvss 4.7epss 0.00

    Capgo before 12.128.2 contains an open redirect vulnerability in the confirm-signup endpoint that allows attackers to redirect users to arbitrary external websites. The confirmation_url parameter is not validated, enabling attackers to craft malicious links for phishing and…

  • CVE-2026-56330LowJun 20, 2026
    risk 0.23cvss 3.5epss 0.00

    Capgo before 12.128.2 contains an open redirect vulnerability in stripe_portal and stripe_checkout endpoints that accept unvalidated callbackUrl, successUrl, and cancelUrl parameters. Authenticated attackers can craft malicious billing URLs to redirect users to…

  • CVE-2026-56310MedJun 24, 2026
    risk 0.21cvss 4.3epss 0.00

    Cap-go before 12.128.2 contains an authorization bypass vulnerability in the GET /organization/members endpoint that allows org-limited API keys to bypass limited_to_orgs restrictions. Attackers with org-limited API keys can read membership data including uid, email, image_url,…

  • CVE-2026-56325LowJun 20, 2026
    risk 0.20cvss 3.1epss 0.00

    Capgo before 12.128.2 uses ILIKE pattern matching instead of exact matching for app_id lookup in the preview subdomain resolver, allowing underscore characters in app_id to act as SQL wildcards. Attackers can create apps with app_ids differing by one character at underscore…

  • CVE-2026-56339HigJul 15, 2026
    risk 0.00cvss 7.5epss 0.00

    Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST SECURITY DEFINER RPC function public.rescind_invitation that allows unauthenticated attackers to enumerate organization existence. The function returns distinct error…

  • CVE-2026-56313HigJul 12, 2026
    risk 0.00cvss 8.1epss 0.01

    Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that allows enterprise administrators to delete password identities of users in foreign organizations. Attackers with org.update_settings permission and an active SSO…

  • CVE-2026-56308HigJul 12, 2026
    risk 0.00cvss 7.3epss 0.00

    Capgo before 12.128.2 allows email address changes without requiring current password re-authentication or verification of the existing email address. An attacker with access to a valid session cookie or authenticated browser can change the account email to gain control of…

  • CVE-2026-56252MedJul 12, 2026
    risk 0.00cvss 5.4epss 0.00

    Capgo before 12.128.2 contains a scope isolation vulnerability in the POST /webhooks/test endpoint that allows app-scoped API keys to invoke org-scoped webhook operations. Attackers with app-scoped credentials can trigger signed outbound webhook deliveries for arbitrary…

  • CVE-2026-56241HigJul 12, 2026
    risk 0.00cvss 8.3epss 0.00

    Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain access to delete_non_compliant_bundles and count_non_compliant_bundles RPCs due to stale org_users.user_right column not being cleared during role binding deletion.…

  • CVE-2026-56238HigJul 12, 2026
    risk 0.00cvss 7.5epss 0.01

    Capgo before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST global_stats endpoint that allows unauthenticated attackers to read sensitive financial and operational metrics using only the public apikey. Remote attackers can query the…

  • CVE-2026-56303HigJul 11, 2026
    risk 0.00cvss 7.5epss 0.00

    Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function marked SECURITY DEFINER and executable by the anon role. Unauthenticated attackers can call this function via the /rest/v1/rpc/find_apikey_by_value endpoint to…

  • CVE-2026-56296MedJul 11, 2026
    risk 0.00cvss 5.3epss 0.00

    Cap-go before 12.128.2 contains an information disclosure vulnerability in the public.transfer_app RPC function that returns distinct error messages for existing versus non-existing app IDs. Unauthenticated attackers can enumerate valid app IDs by observing error message…

  • CVE-2026-56240MedJul 11, 2026
    risk 0.00cvss 4.3epss 0.00

    Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows organizations with exhausted or expired usage credit grants to bypass billing gates. Attackers can exploit the divergence between the plugin hot-path plan_valid…

  • CVE-2026-56335MedJul 10, 2026
    risk 0.00cvss 6.5epss 0.00

    Capgo before 12.128.2 contains an authorization bypass vulnerability where write-scoped API keys can directly mutate protected channel configuration fields through PostgREST by exploiting a null authentication check in the immutability trigger. Attackers with write API keys can…

  • CVE-2026-56329MedJul 10, 2026
    risk 0.00cvss 6.4epss 0.00

    Capgo before 12.128.2 contains a cross-tenant preview namespace collision vulnerability caused by non-bijective decoding of double underscores to dots in preview hostname parsing. Attackers can register app IDs with underscores that collide with other tenants' dotted app IDs,…

  • CVE-2026-56312MedJul 10, 2026
    risk 0.00cvss 6.5epss 0.00

    Capgo before 12.128.2 contains an improper validation vulnerability in the accept_invitation endpoint that creates user accounts before captcha validation is enforced. Attackers can bypass captcha protection by sending POST requests with invalid captcha tokens to create unwanted…

  • CVE-2026-56309MedJul 10, 2026
    risk 0.00cvss 5.4epss 0.00

    Capgo before 12.128.2 fails to enforce plan/quota restrictions on the /files/upload/attachments endpoint, allowing plan-blocked apps to create publicly readable R2 objects. Attackers can upload arbitrary attachments using upload-scoped API keys that bypass plan checks, persist…

  • CVE-2026-56305HigJul 10, 2026
    risk 0.00cvss 8.3epss 0.01

    Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attackers to change user passwords without requiring current password confirmation. Attackers with temporary session access can exploit this flaw to permanently lock…

  • CVE-2026-56279HigJul 10, 2026
    risk 0.00cvss 7.5epss 0.00

    Capgo before 12.128.2 contains an information disclosure vulnerability in the get_orgs_v7(userid) RPC function that remains publicly invokable despite intended private access controls. Unauthenticated attackers can supply arbitrary user UUIDs to retrieve foreign users'…

  • CVE-2026-56254HigJul 10, 2026
    risk 0.00cvss 7.0epss 0.00

    In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app. Because the public key can be derived from the private key, an attacker performing a man-in-the-middle attack or…

Page 4 of 6