VYPR

Vendor CVEs

Cap Go

All CVEs

108 total · sorted by risk
  • CVE-2026-56213MedJun 20, 2026
    risk 0.34cvss 5.3epss 0.00

    Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.upsert_version_meta SECURITY DEFINER function exposed via PostgREST RPC, allowing unauthenticated attackers to insert arbitrary rows into version_meta for any app_id. Attackers can exploit this by…

  • CVE-2026-56228MedJun 20, 2026
    risk 0.32cvss 4.9epss 0.00

    Capgo before 12.128.2 fails to enforce a maximum value on the minimum password length field in its password policy configuration. An authenticated organization administrator can set an extremely large numeric value (e.g., billions of characters) as the minimum password length,…

  • CVE-2026-56080MedJun 19, 2026
    risk 0.32cvss 4.9epss 0.01

    Capgo before 12.128.2 contains a flaw in the Enforce Password Policy feature: after a Super Admin enables the policy and successfully changes their password to a compliant one, the backend does not update the password-compliance state. As a result, the backend continues to treat…

  • CVE-2026-56294MedJun 20, 2026
    risk 0.31cvss 4.8epss 0.00

    capacitor-native-biometric before 12.128.2 contains an authentication bypass vulnerability where the onAuthenticationSucceeded() method fails to validate CryptoObject parameters. Attackers can hook the onAuthenticationSucceeded() function using dynamic instrumentation to bypass…

  • CVE-2026-56255MedJun 22, 2026
    risk 0.28cvss 4.3epss 0.00

    Capgo before 12.128.2 contains a denial of service vulnerability in the POST /app/demo endpoint that allows authenticated users with org write permissions to create unlimited demo applications without rate limiting or quota enforcement. Attackers can repeatedly invoke this…

  • CVE-2026-56319MedJun 20, 2026
    risk 0.28cvss 4.3epss 0.00

    Capgo before 12.128.2 contains an information disclosure vulnerability in the GET /statistics/app/:app_id endpoint that allows app-limited API keys to distinguish existing sibling app IDs through differential error responses. Attackers can enumerate real app IDs outside their…

  • CVE-2026-56307MedJun 20, 2026
    risk 0.28cvss 4.3epss 0.00

    Cap-go before 12.128.12 contains a broken cursor pagination vulnerability in the /private/devices endpoint on the Cloudflare/workerd path that allows authenticated attackers to cause duplicate-page loops and make later rows unreachable. Attackers with app.read_devices access can…

  • CVE-2026-53867MedJun 12, 2026
    risk 0.28cvss 4.3epss 0.00

    Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remove them. Attackers can access orphaned image files through previously generated URLs, allowing unauthorized retrieval of user-uploaded content.

  • CVE-2026-56338MedJun 24, 2026
    risk 0.27cvss 5.3epss 0.00

    Capgo before 12.128.2 contains a denial of service vulnerability in the /auth/v1/otp endpoint that prevents email verification for two-factor authentication due to captcha validation failures. Authenticated users cannot complete 2FA enrollment as the backend consistently returns…

  • CVE-2026-56337MedJun 24, 2026
    risk 0.27cvss 5.3epss 0.00

    Capgo before 12.128.2 contains an information disclosure vulnerability in the public.exist_app_v2 RPC function that allows unauthenticated attackers to enumerate app_ids by calling POST /rest/v1/rpc/exist_app_v2 with arbitrary appid parameters. Remote attackers can exploit this…

  • CVE-2026-56234MedJun 23, 2026
    risk 0.27cvss 5.3epss 0.00

    Capgo before 12.128.2 contains a credential validation vulnerability in the POST /functions/v1/private/validate_password_compliance endpoint that is callable using only the public Supabase key without authentication. The endpoint is CORS-permissive with wildcard origin allowance…

  • CVE-2026-56212LowJun 20, 2026
    risk 0.25cvss 3.8epss 0.00

    Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organization security settings can enable mandatory two-factor authentication for all team members without first enabling 2FA on their own account. The application fails to…

  • CVE-2026-56332MedJun 20, 2026
    risk 0.24cvss 4.7epss 0.00

    Capgo before 12.128.2 contains an open redirect vulnerability in the confirm-signup endpoint that allows attackers to redirect users to arbitrary external websites. The confirmation_url parameter is not validated, enabling attackers to craft malicious links for phishing and…

  • CVE-2026-56330LowJun 20, 2026
    risk 0.23cvss 3.5epss 0.00

    Capgo before 12.128.2 contains an open redirect vulnerability in stripe_portal and stripe_checkout endpoints that accept unvalidated callbackUrl, successUrl, and cancelUrl parameters. Authenticated attackers can craft malicious billing URLs to redirect users to…

  • CVE-2026-56310MedJun 24, 2026
    risk 0.21cvss 4.3epss 0.00

    Cap-go before 12.128.2 contains an authorization bypass vulnerability in the GET /organization/members endpoint that allows org-limited API keys to bypass limited_to_orgs restrictions. Attackers with org-limited API keys can read membership data including uid, email, image_url,…

  • CVE-2026-56325LowJun 20, 2026
    risk 0.20cvss 3.1epss 0.00

    Capgo before 12.128.2 uses ILIKE pattern matching instead of exact matching for app_id lookup in the preview subdomain resolver, allowing underscore characters in app_id to act as SQL wildcards. Attackers can create apps with app_ids differing by one character at underscore…

  • CVE-2026-56339HigJul 15, 2026
    risk 0.00cvss 7.5epss 0.00

    Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST SECURITY DEFINER RPC function public.rescind_invitation that allows unauthenticated attackers to enumerate organization existence. The function returns distinct error…

  • CVE-2026-56336MedJul 12, 2026
    risk 0.00cvss 5.3epss 0.00

    Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain endpoint that returns internal org_id and provider_id values. Attackers can enumerate email domains to build mappings of domains to organization UUIDs and SSO…

  • CVE-2026-56313HigJul 12, 2026
    risk 0.00cvss 8.1epss 0.01

    Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoint that allows enterprise administrators to delete password identities of users in foreign organizations. Attackers with org.update_settings permission and an active SSO…

  • CVE-2026-56308HigJul 12, 2026
    risk 0.00cvss 7.3epss 0.00

    Capgo before 12.128.2 allows email address changes without requiring current password re-authentication or verification of the existing email address. An attacker with access to a valid session cookie or authenticated browser can change the account email to gain control of…

  • CVE-2026-56281LowJul 12, 2026
    risk 0.00cvss 3.8epss 0.00

    Capgo before 12.128.2 contains a sql injection vulnerability in the POST /private/admin_stats endpoint where the limit parameter is destructured from unvalidated request body and interpolated directly into Cloudflare Analytics Engine SQL queries via template literals. An…

  • CVE-2026-56252MedJul 12, 2026
    risk 0.00cvss 5.4epss 0.00

    Capgo before 12.128.2 contains a scope isolation vulnerability in the POST /webhooks/test endpoint that allows app-scoped API keys to invoke org-scoped webhook operations. Attackers with app-scoped credentials can trigger signed outbound webhook deliveries for arbitrary…

  • CVE-2026-56241HigJul 12, 2026
    risk 0.00cvss 8.3epss 0.00

    Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain access to delete_non_compliant_bundles and count_non_compliant_bundles RPCs due to stale org_users.user_right column not being cleared during role binding deletion.…

  • CVE-2026-56238HigJul 12, 2026
    risk 0.00cvss 7.5epss 0.01

    Capgo before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST global_stats endpoint that allows unauthenticated attackers to read sensitive financial and operational metrics using only the public apikey. Remote attackers can query the…

  • CVE-2026-56303HigJul 11, 2026
    risk 0.00cvss 7.5epss 0.00

    Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL function marked SECURITY DEFINER and executable by the anon role. Unauthenticated attackers can call this function via the /rest/v1/rpc/find_apikey_by_value endpoint to…

  • CVE-2026-56296MedJul 11, 2026
    risk 0.00cvss 5.3epss 0.00

    Cap-go before 12.128.2 contains an information disclosure vulnerability in the public.transfer_app RPC function that returns distinct error messages for existing versus non-existing app IDs. Unauthenticated attackers can enumerate valid app IDs by observing error message…

  • CVE-2026-56240MedJul 11, 2026
    risk 0.00cvss 4.3epss 0.00

    Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation that allows organizations with exhausted or expired usage credit grants to bypass billing gates. Attackers can exploit the divergence between the plugin hot-path plan_valid…

  • CVE-2026-56335MedJul 10, 2026
    risk 0.00cvss 6.5epss 0.00

    Capgo before 12.128.2 contains an authorization bypass vulnerability where write-scoped API keys can directly mutate protected channel configuration fields through PostgREST by exploiting a null authentication check in the immutability trigger. Attackers with write API keys can…

  • CVE-2026-56329MedJul 10, 2026
    risk 0.00cvss 6.4epss 0.00

    Capgo before 12.128.2 contains a cross-tenant preview namespace collision vulnerability caused by non-bijective decoding of double underscores to dots in preview hostname parsing. Attackers can register app IDs with underscores that collide with other tenants' dotted app IDs,…

  • CVE-2026-56312MedJul 10, 2026
    risk 0.00cvss 6.5epss 0.00

    Capgo before 12.128.2 contains an improper validation vulnerability in the accept_invitation endpoint that creates user accounts before captcha validation is enforced. Attackers can bypass captcha protection by sending POST requests with invalid captcha tokens to create unwanted…

  • CVE-2026-56309MedJul 10, 2026
    risk 0.00cvss 5.4epss 0.00

    Capgo before 12.128.2 fails to enforce plan/quota restrictions on the /files/upload/attachments endpoint, allowing plan-blocked apps to create publicly readable R2 objects. Attackers can upload arbitrary attachments using upload-scoped API keys that bypass plan checks, persist…

  • CVE-2026-56305HigJul 10, 2026
    risk 0.00cvss 8.3epss 0.01

    Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attackers to change user passwords without requiring current password confirmation. Attackers with temporary session access can exploit this flaw to permanently lock…

  • CVE-2026-56279HigJul 10, 2026
    risk 0.00cvss 7.5epss 0.00

    Capgo before 12.128.2 contains an information disclosure vulnerability in the get_orgs_v7(userid) RPC function that remains publicly invokable despite intended private access controls. Unauthenticated attackers can supply arbitrary user UUIDs to retrieve foreign users'…

  • CVE-2026-56254HigJul 10, 2026
    risk 0.00cvss 7.0epss 0.00

    In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app. Because the public key can be derived from the private key, an attacker performing a man-in-the-middle attack or…

  • CVE-2026-56298MedJul 8, 2026
    risk 0.00cvss 4.3epss 0.00

    Capgo before 12.128.2 fails to strip EXIF metadata from images uploaded via the app information endpoint, exposing sensitive geolocation data. Attackers can upload images containing EXIF metadata to extract geographic location information and other embedded metadata from…

  • CVE-2026-56293MedJul 8, 2026
    risk 0.00cvss 5.4epss 0.00

    Capgo before 12.128.2 contains an authorization flaw in transfer_app() that fails to update deploy_history.owner_org when transferring applications between organizations. Attackers can exploit this omission to retain unauthorized access to deployment history records in the…

  • CVE-2026-56284MedJul 8, 2026
    risk 0.00cvss 5.3epss 0.00

    Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST RPC function public.get_total_metrics(org_id), which is callable by the anon role using only the public sb_publishable_* key. An unauthenticated attacker can probe…

  • CVE-2026-56283MedJul 8, 2026
    risk 0.00cvss 5.4epss 0.00

    Capgo before 12.128.2 contains an html injection vulnerability in the organization settings endpoint that allows attackers to inject malicious HTML content. Attackers can craft payloads in the organization name field to redirect users to untrusted websites, enabling phishing…

  • CVE-2026-56250HigJul 8, 2026
    risk 0.00cvss 7.5epss 0.00

    Capgo before 12.128.2 allows upload-scoped API keys to modify the mutable app_versions.r2_path field through PostgREST, enabling retargeting to arbitrary R2 bundle objects. Attackers can patch r2_path to point to victim objects, soft-delete the attacker-controlled version, and…

  • CVE-2026-56246HigJul 8, 2026
    risk 0.00cvss 8.1epss 0.00

    Capgo before 12.128.2 contains a broken access control vulnerability in the organization management API where a scoped API key (limited_to_orgs) inherits its owner-user's permissions, allowing destructive cross-organization actions. When a user is an admin in two organizations…

  • CVE-2026-56226HigJul 8, 2026
    risk 0.00cvss 7.5epss 0.00

    Capgo (Cap-go/capgo) before 12.128.2 exposes the Supabase PostgREST RPC function public.get_orgs_v6(userid uuid), which is SECURITY DEFINER and granted to the anon role, allowing unauthenticated access. Because the function accepts a caller-supplied user UUID without verifying…

  • CVE-2026-56220MedJul 8, 2026
    risk 0.00cvss 6.5epss 0.00

    Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.manifest INSERT policy that allows read-only org members to insert OTA manifest rows. Attackers with read-only org access can inject malicious manifest entries with arbitrary s3_path values that…

  • CVE-2026-56217MedJul 8, 2026
    risk 0.00cvss 4.3epss 0.00

    Capgo before 12.128.2 contains a policy bypass vulnerability in app_versions update enforcement that allows app-scoped API keys to downgrade encrypted bundles to non-encrypted state. Attackers with app-scoped all API keys can directly update the app_versions table via PostgREST…

  • CVE-2026-56334MedJun 30, 2026
    risk 0.00cvss 4.3epss 0.00

    Capgo before 12.128.2 lacks an UPDATE row-level security policy for the build_requests table, preventing API-key and anonymous access from persisting builder status updates. Attackers can exploit this missing policy to cause build status and error details to remain unpersisted,…

  • CVE-2026-56333MedJun 30, 2026
    risk 0.00cvss 4.3epss 0.00

    Capgo before 12.128.2 contains a server-side validation bypass vulnerability in organization security settings that allows authenticated org admins to persist invalid security policy state. Attackers can bypass backend validation by directly updating the public.orgs table from…

  • CVE-2026-56331MedJun 30, 2026
    risk 0.00cvss 5.3epss 0.00

    Capgo before 12.128.2 contains improper error handling in the /private/accept_invitation endpoint that returns HTTP 500 instead of safe 4xx errors when magic_invite_string is invalid. Attackers can trigger this vulnerability using only the public key by submitting malformed…

  • CVE-2026-56328MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    Capgo before 12.128.2 allows multiple public channels for the same app and platform to coexist simultaneously, while unnamed /updates requests without defaultChannel implicitly resolve to a single hidden winner channel. An authorized app or channel manager can create ambiguous…

  • CVE-2026-56327MedJun 30, 2026
    risk 0.00cvss 5.3epss 0.00

    Capgo before 12.128.2 contains an information disclosure vulnerability in the public.invite_user_to_org RPC function that allows unauthenticated attackers to enumerate organization existence by observing distinct error responses. Attackers can call the SECURITY DEFINER function…

  • CVE-2026-56320HigJun 30, 2026
    risk 0.00cvss 7.1epss 0.00

    Capgo before 12.128.2 contains an authorization flaw in POST /private/create_device that accepts a caller-supplied org_id parameter without validating it matches the target app's owner organization. Authenticated attackers can create device records for an application using a…

  • CVE-2026-56318MedJun 30, 2026
    risk 0.00cvss 5.3epss 0.00

    Capgo before 12.128.2 contains an information disclosure vulnerability in the /private/validate_password_compliance endpoint that returns different error responses for malformed, non-existent, and existing organization IDs. Unauthenticated attackers can enumerate valid…