PatchSiren

Cap-go CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Cap-go CVE published 2026-07-11

CVE-2026-56296

CVE-2026-56296 is an information disclosure vulnerability in Cap-go before 12.128.2. The public.transfer_app RPC function returns distinct error messages for existing versus non-existing app IDs. Unauthenticated attackers can enumerate valid app IDs by observing error message differences when calling transfer_app with only the publishable API key. This vulnerability allows attackers to potentially identif [truncated]

MEDIUM Cap-go CVE published 2026-07-08

CVE-2026-56284

The CVE record for CVE-2026-56284 was published on 2026-07-08T14:17:16.100Z and has not been modified since then. The NVD entry is currently Deferred. This information disclosure vulnerability in Capgo (Cap-go/capgo) before version 12.128.2 allows unauthenticated attackers to probe organization existence and leak sensitive usage metrics. The vulnerability is related to the Supabase PostgREST RPC function [truncated]

HIGH Cap-go CVE published 2026-06-23

CVE-2026-56248

CVE-2026-56248 is an unauthenticated denial-of-service vulnerability in Cap-go capgo (capgo-backend) before 12.128.12. The vulnerability arises from the audit_logs table's Row-Level Security (RLS) policy when accessed via the Supabase PostgREST API. Unfiltered queries to the public.audit_logs endpoint using the public anon key consistently trigger statement timeouts. Under concurrency, this exhausts datab [truncated]

HIGH Cap-go CVE published 2026-06-22

CVE-2026-56221

CVE-2026-56221 is a high-severity vulnerability in Cap-go, a cloudflare analytics engine. The vulnerability exists in the cloudflare.ts file, where user-controlled values from API request bodies are interpolated directly into SQL query strings without sanitization or parameterization. This allows authenticated users with read-level API key permissions to inject arbitrary SQL and access analytics data belo [truncated]

MEDIUM Cap-go CVE published 2026-06-21

CVE-2026-56316

CVE-2026-56316 is a medium-severity information disclosure vulnerability in Cap-go versions before 12.128.2. The vulnerability exists in the OPTIONS /build/upload/:jobId/* endpoint, allowing unauthenticated attackers to enumerate valid builder job IDs through observable response discrepancies. This issue has a CVSS score of 6.9. The vulnerability was published on June 21, 2026. Affected users should revie [truncated]

MEDIUM Cap-go CVE published 2026-06-20

CVE-2026-56235

CVE-2026-56235 is a MEDIUM-severity vulnerability in Cap-go capgo before version 12.128.2. An authorization bypass in several Supabase PostgREST RPC functions allows unauthenticated attackers to disclose cross-tenant usage telemetry and enumerate app IDs. The vulnerability has a CVSS score of 6.9. Affected organizations should prioritize patching to limit exposure. The disclosure was made on June 20, 2026.

CRITICAL Cap-go CVE published 2026-06-19

CVE-2026-56081

CVE-2026-56081 is a critical authentication logic flaw in Cap-go before version 12.128.2. The vulnerability allows an attacker to register and control an account bound to a victim's email address before the email is verified. By enabling two-factor authentication on the pre-registered account, the attacker gains control over the account claimed under the victim's identity. This enables the attacker to rea [truncated]

CRITICAL Cap-go CVE published 2026-06-19

CVE-2026-56073

CVE-2026-56073 is an authentication bypass vulnerability in Cap-go's OTP verification process. Attackers can manipulate server responses to bypass email and 2FA, potentially leading to account takeovers. The vulnerability affects Cap-go versions before 12.128.2. Organizations using Cap-go's capgo product should prioritize patching to prevent potential account takeovers. The CVE record was published on 202 [truncated]

MEDIUM Cap-go CVE published 2026-06-12

CVE-2026-53867

CVE-2026-53867 is a medium-severity vulnerability in Capgo, a cloud-based service. The issue arises from Capgo's failure to delete previously uploaded profile images from backend storage when users replace or remove them. This oversight allows attackers to access orphaned image files through previously generated URLs, enabling unauthorized retrieval of user-uploaded content. The vulnerability has a CVSS s [truncated]

HIGH Cap-go CVE published 2026-06-12

CVE-2026-53982

CVE-2026-53982 is a high-severity denial-of-service vulnerability in Cap-go Console < 12.28.2. The vulnerability allows an attacker to block authentication and onboarding functions by triggering account deletion while a device identifier is linked to the active session. The platform incorrectly associates the deletion state with the device identifier, causing the affected device or browser environment to [truncated]

HIGH Cap-go CVE published 2026-06-12

CVE-2026-53981

CVE-2026-53981 is a HIGH severity vulnerability in Cap-go prior to 12.128.2. The vulnerability exists in the email change mechanism, allowing an attacker with temporary authenticated session access to change the registered email address without re-authentication, such as password or MFA verification. This enables attackers to redirect verification to an attacker-controlled email address and subsequently p [truncated]