Capgo
83 CVEsCVE IDSeverityProduct / summaryPublished
CVE-2026-56238
HIGH 8.7
Capgo — Capgo before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST global_stats …● PoC
2026-07-12
CVE-2026-56241
HIGH 7.2
Capgo — Capgo before 12.128.2 contains a privilege escalation vulnerability where demoted super_admin users retain acc…● PoC
2026-07-12
CVE-2026-56252
MEDIUM 5.3
Capgo — Capgo before 12.128.2 contains a scope isolation vulnerability in the POST /webhooks/test endpoint that allows…● PoC
2026-07-12
CVE-2026-56281
MEDIUM 5.1
Capgo — Capgo before 12.128.2 contains a sql injection vulnerability in the POST /private/admin_stats endpoint where t…● PoC
2026-07-12
CVE-2026-56308
HIGH 8.4
Capgo — Capgo before 12.128.2 allows email address changes without requiring current password re-authentication or ver…● PoC
2026-07-12
CVE-2026-56313
HIGH 7.2
Capgo — Capgo before 12.128.2 contains a cross-organization account disruption vulnerability in the SSO prelink endpoi…
2026-07-12
CVE-2026-56336
MEDIUM 6.9
Capgo — Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/che…● PoC
2026-07-12
CVE-2026-56240
MEDIUM 5.3
Capgo — Capgo before 12.128.12 contains a billing authorization bypass vulnerability in the plan_valid calculation tha…● PoC
2026-07-11
CVE-2026-56303
HIGH 8.7
Capgo — Capgo before 12.128.2 contains an information disclosure vulnerability in the find_apikey_by_value PostgreSQL …● PoC
2026-07-11
CVE-2026-56279
HIGH 8.7
Capgo — Capgo before 12.128.2 contains an information disclosure vulnerability in the get_orgs_v7(userid) RPC function…● PoC
2026-07-10
CVE-2026-56305
HIGH 8.7
Capgo — Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that all…● PoC
2026-07-10
CVE-2026-56309
MEDIUM 5.3
Capgo — Capgo before 12.128.2 fails to enforce plan/quota restrictions on the /files/upload/attachments endpoint, allo…● PoC
2026-07-10
CVE-2026-56312
MEDIUM 6.9
Capgo — Capgo before 12.128.2 contains an improper validation vulnerability in the accept_invitation endpoint that cre…
2026-07-10
CVE-2026-56329
MEDIUM 5.3
Capgo — Capgo before 12.128.2 contains a cross-tenant preview namespace collision vulnerability caused by non-bijectiv…● PoC
2026-07-10
CVE-2026-56335
HIGH 7.1
Capgo — Capgo before 12.128.2 contains an authorization bypass vulnerability where write-scoped API keys can directly …● PoC
2026-07-10
CVE-2026-56217
MEDIUM 5.3
Capgo — Capgo before 12.128.2 contains a policy bypass vulnerability in app_versions update enforcement that allows ap…● PoC
2026-07-08
CVE-2026-56220
HIGH 7.1
Capgo — Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.manifest INSERT policy that…● PoC
2026-07-08
CVE-2026-56246
HIGH 7.2
Capgo — Capgo before 12.128.2 contains a broken access control vulnerability in the organization management API where …● PoC
2026-07-08
CVE-2026-56250
HIGH 8.7
Capgo — Capgo before 12.128.2 allows upload-scoped API keys to modify the mutable app_versions.r2_path field through P…● PoC
2026-07-08
CVE-2026-56283
MEDIUM 4.8
Capgo — Capgo before 12.128.2 contains an html injection vulnerability in the organization settings endpoint that allo…● PoC
2026-07-08
CVE-2026-56293
MEDIUM 5.3
Capgo — Capgo before 12.128.2 contains an authorization flaw in transfer_app() that fails to update deploy_history.own…● PoC
2026-07-08
CVE-2026-56298
MEDIUM 5.3
Capgo — Capgo before 12.128.2 fails to strip EXIF metadata from images uploaded via the app information endpoint, expo…
2026-07-08
CVE-2026-56219
HIGH 8.7
Capgo — Capgo before 12.128.2 contains a NULL-auth bypass vulnerability in the public.get_org_user_access_rbac functio…● PoC
2026-06-30
CVE-2026-56224
MEDIUM 5.1
Capgo — Capgo console.capgo.app/login before 12.128.2 accepts access_token and refresh_token in URL query parameters, …● PoC
2026-06-30
CVE-2026-56230
HIGH 8.7
Capgo — Capgo before 12.128.2 contains a broken object level authorization vulnerability in middlewareKey() that accep…
2026-06-30
CVE-2026-56233
HIGH 8.7
Capgo — Capgo before 12.128.2 contains a path traversal vulnerability in the builder upload proxy that allows authenti…● PoC
2026-06-30
CVE-2026-56247
HIGH 8.7
Capgo — Capgo before 12.128.2 allows org admins to assign org-scoped RBAC roles at app scope without validating role s…● PoC
2026-06-30
CVE-2026-56249
HIGH 7.2
Capgo — Capgo before 12.128.2 contains an authorization bypass vulnerability in the channel creation endpoint that all…● PoC
2026-06-30
CVE-2026-56286
HIGH 7
Capgo — Capgo before 12.128.2 contains an authentication bypass vulnerability in the account deletion endpoint that al…● PoC
2026-06-30
CVE-2026-56300
HIGH 8.7
Capgo — Capgo before 12.128.2 contains unauthenticated security definer RPC functions get_user_id and get_org_perm_for…● PoC
2026-06-30
CVE-2026-56318
MEDIUM 6.9
Capgo — Capgo before 12.128.2 contains an information disclosure vulnerability in the /private/validate_password_compl…● PoC
2026-06-30
CVE-2026-56320
HIGH 7.1
Capgo — Capgo before 12.128.2 contains an authorization flaw in POST /private/create_device that accepts a caller-supp…● PoC
2026-06-30
CVE-2026-56327
MEDIUM 6.9
Capgo — Capgo before 12.128.2 contains an information disclosure vulnerability in the public.invite_user_to_org RPC fu…● PoC
2026-06-30
CVE-2026-56328
HIGH 7.1
Capgo — Capgo before 12.128.2 allows multiple public channels for the same app and platform to coexist simultaneously,…● PoC
2026-06-30
CVE-2026-56331
MEDIUM 6.9
Capgo — Capgo before 12.128.2 contains improper error handling in the /private/accept_invitation endpoint that returns…● PoC
2026-06-30
CVE-2026-56333
MEDIUM 5.3
Capgo — Capgo before 12.128.2 contains a server-side validation bypass vulnerability in organization security settings…● PoC
2026-06-30
CVE-2026-56334
MEDIUM 5.3
Capgo — Capgo before 12.128.2 lacks an UPDATE row-level security policy for the build_requests table, preventing API-k…● PoC
2026-06-30
CVE-2026-56223
CRITICAL 9.3
Capgo — Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoin…● PoC
2026-06-24
CVE-2026-56231
HIGH 7.2
Capgo — Capgo before 12.128.2 contains a broken object level authorization (BOLA) vulnerability in the POST /build/sta…● PoC
2026-06-24
CVE-2026-56232
HIGH 8.7
Capgo — Capgo before 12.128.2 fails to enforce limited_to_orgs and limited_to_apps constraints on subkeys provided via…● PoC
2026-06-24
CVE-2026-56237
CRITICAL 9.3
Capgo — Capgo before 12.128.2 contains a broken authentication vulnerability in its API key generation mechanism. API …● PoC
2026-06-24
CVE-2026-56244
HIGH 7.1
Capgo — Capgo before 12.128.2 allows non-admin API keys to read webhook signing secrets via Supabase REST due to insuf…● PoC
2026-06-24
CVE-2026-56256
HIGH 7.1
Capgo — Capgo before 12.128.2 enforces mandatory two-factor authentication only at the UI level. Sensitive Organizatio…● PoC
2026-06-24
CVE-2026-56257
HIGH 7.1
Capgo — Capgo before 12.128.2 allows direct patching of public.apps.owner_org through PostgREST, bypassing the transfe…● PoC
2026-06-24
CVE-2026-56302
MEDIUM 6.9
Capgo — Capgo before 12.128.2 contains an unsecured images bucket lacking any row level security controls, allowing un…● PoC
2026-06-24
CVE-2026-56337
MEDIUM 6.9
Capgo — Capgo before 12.128.2 contains an information disclosure vulnerability in the public.exist_app_v2 RPC function…● PoC
2026-06-24
CVE-2026-56338
MEDIUM 6.9
Capgo — Capgo before 12.128.2 contains a denial of service vulnerability in the /auth/v1/otp endpoint that prevents em…● PoC
2026-06-24
CVE-2026-56222
HIGH 8.6
Capgo — Capgo before 12.128.2 contains an authorization bypass vulnerability in POST /private/role_bindings that fails…● PoC
2026-06-23
CVE-2026-56225
HIGH 8.7
Capgo — Capgo before 12.128.2 contains an authorization bypass vulnerability in its public API key management handlers…● PoC
2026-06-23
CVE-2026-56234
MEDIUM 6.9
Capgo — Capgo before 12.128.2 contains a credential validation vulnerability in the POST /functions/v1/private/validat…● PoC
2026-06-23
CVE-2026-56243
HIGH 8.6
Capgo — Capgo before 12.128.2 contains a security control bypass vulnerability where the PostgREST/RLS plane accepts p…● PoC
2026-06-23
CVE-2026-56322
HIGH 8.7
Capgo — Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /updates endpoin…● PoC
2026-06-23
CVE-2026-56255
MEDIUM 5.3
Capgo — Capgo before 12.128.2 contains a denial of service vulnerability in the POST /app/demo endpoint that allows au…● PoC
2026-06-22
CVE-2026-56306
MEDIUM 5.3
Capgo — Capgo before 12.128.2 contains a weak parsing vulnerability in the x-limited-key-id header that allows attacke…● PoC
2026-06-22
CVE-2026-56311
MEDIUM 6.9
Capgo — Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.get_current_plan_max_org RP…● PoC
2026-06-22
CVE-2026-56314
HIGH 7.1
Capgo — Capgo before 12.128.12 fails to filter deleted app versions when joining channels during /updates resolution, …● PoC
2026-06-22
CVE-2026-56321
MEDIUM 6.9
Capgo — Capgo (backend Supabase edge functions) before 12.128.2 does not apply the global authentication middleware to…● PoC
2026-06-22
CVE-2026-56323
HIGH 8.7
Capgo — Capgo before 12.128.2 contains an information disclosure vulnerability in the /functions/v1/channel_self endpo…● PoC
2026-06-22
CVE-2026-56324
HIGH 8.8
Capgo — Capgo before 12.128.2 contains a rate limit bypass vulnerability in the channel_self endpoint that allows atta…● PoC
2026-06-22
CVE-2026-56229
HIGH 7.1
Capgo — Capgo before 12.128.2 contains an authorization bypass vulnerability in the /build/status and /build/logs endp…● PoC
2026-06-21
CVE-2026-56236
MEDIUM 6.8
Cli — Capgo CLI before 12.128.2 contains arbitrary file overwrite vulnerabilities in login and build credentials ope…
2026-06-21
CVE-2026-56239
HIGH 7.2
Capgo — Capgo before 12.128.2 contains a potential privilege escalation vulnerability in the public.apply_usage_overag…● PoC
2026-06-21
CVE-2026-56242
HIGH 8.7
Capgo — Capgo before 12.128.2 contains an unauthenticated security definer RPC function get_identity_apikey_only that …● PoC
2026-06-21
CVE-2026-56251
HIGH 7
Capgo — Capgo before 12.128.2 contains a broken row level security policy in the org_users table that allows authentic…
2026-06-21
CVE-2026-56253
HIGH 8.7
Capgo — Capgo before 12.128.2 contains an improper access control vulnerability in the public.get_org_members RPC func…● PoC
2026-06-21
CVE-2026-56299
MEDIUM 6.9
Capgo — Capgo before 12.128.2 contains an authentication bypass vulnerability in the /build/upload/:jobId/* endpoint t…
2026-06-21
CVE-2026-56212
MEDIUM 5.1
Capgo — Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organiza…
2026-06-20
CVE-2026-56213
MEDIUM 6.9
Capgo — Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.upsert_version_meta SECURIT…
2026-06-20
CVE-2026-56214
HIGH 8.7
Capgo — Capgo before 12.128.2 contains an information disclosure vulnerability in Supabase PostgREST RPC endpoints is_…● PoC
2026-06-20
CVE-2026-56215
HIGH 8.7
Capgo — Capgo before 12.128.12 allows authenticated users to modify their mutable public.users.email to arbitrary addr…● PoC
2026-06-20
CVE-2026-56216
HIGH 8.7
Capgo — Capgo before 12.128.2 contains a scope escalation vulnerability in the POST /functions/v1/apikey endpoint that…● PoC
2026-06-20
CVE-2026-56218
MEDIUM 6.9
Capgo — Capgo before 12.128.2 fails to strip EXIF metadata including GPS geolocation data from uploaded images, allowi…● PoC
2026-06-20
CVE-2026-56227
MEDIUM 5.3
Capgo — Capgo before 12.128.2 contains a server-side request forgery vulnerability in webhook URL validation that allo…● PoC
2026-06-20
CVE-2026-56228
MEDIUM 6.9
Capgo — Capgo before 12.128.2 fails to enforce a maximum value on the minimum password length field in its password po…
2026-06-20
CVE-2026-56282
MEDIUM 6.9
Capgo — Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /replication end…● PoC
2026-06-20
CVE-2026-56295
MEDIUM 5.3
Capgo — Capgo before 12.128.2 contains an authorization bypass vulnerability in webhook management endpoints that allo…● PoC
2026-06-20
CVE-2026-56319
MEDIUM 5.3
Capgo — Capgo before 12.128.2 contains an information disclosure vulnerability in the GET /statistics/app/:app_id endp…● PoC
2026-06-20
CVE-2026-56325
LOW 2.3
Capgo — Capgo before 12.128.2 uses ILIKE pattern matching instead of exact matching for app_id lookup in the preview s…● PoC
2026-06-20
CVE-2026-56330
MEDIUM 4.8
Capgo — Capgo before 12.128.2 contains an open redirect vulnerability in stripe_portal and stripe_checkout endpoints t…● PoC
2026-06-20
CVE-2026-56332
MEDIUM 5.1
Capgo — Capgo before 12.128.2 contains an open redirect vulnerability in the confirm-signup endpoint that allows attac…● PoC
2026-06-20
CVE-2026-56079
HIGH 7.1
Capgo — Capgo before 12.128.2 contains a cross-tenant authorization bypass vulnerability in PostgREST endpoints that a…● PoC
2026-06-19
CVE-2026-53867
MEDIUM 5.3
Capgo — Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users repla…
2026-06-12
CVE-2026-53868
HIGH 8.7
Capgo — Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using…
2026-06-12