These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-56253 is a high-severity vulnerability in Capgo, a product of unknown vendor, that allows unauthenticated attackers to enumerate organization members. The vulnerability exists in the public.get_org_members RPC function and can be exploited using only the public sb_publishable_* key and an organization UUID. This exposure can lead to the retrieval of sensitive member information, including email a [truncated]
CVE-2026-56251 is a HIGH-severity vulnerability in Capgo before version 12.128.2. The issue is a broken row-level security policy in the org_users table, which allows authenticated users to elevate privileges from admin to super_admin. This could lead to unauthorized access and compromise system security. Organizations using affected Capgo versions should prioritize patching to limit exposure.
CVE-2026-56242 is a HIGH-severity vulnerability in Capgo, a product with an unauthenticated security definer RPC function get_identity_apikey_only. This function returns the owning user_id for supplied API keys, creating an API key validity oracle and user identity disclosure primitive. The vulnerability allows attackers to confirm key validity and map keys to user identifiers, potentially leading to furt [truncated]
CVE-2026-56236 is a medium-severity vulnerability in Capgo CLI versions before 12.128.2. The vulnerability allows attackers to overwrite arbitrary files or expose credentials with world-readable permissions when developers run the CLI. The issue arises from the CLI's handling of symlinks in repositories without proper validation. This vulnerability has a CVSS score of 6.8 and is classified as CWE-59. Orga [truncated]
CVE-2026-56229 is a high-severity authorization bypass vulnerability in Capgo, a mobile app development platform. The vulnerability exists in the /build/status and /build/logs endpoints, allowing attackers to access build jobs belonging to different applications by supplying a mismatched app_id and job_id combination. This issue affects Capgo versions before 12.128.2. Defenders should prioritize patching [truncated]
CVE-2026-56332 is a medium-severity open redirect vulnerability in Capgo before version 12.128.2. The vulnerability exists in the confirm-signup endpoint and allows attackers to redirect users to arbitrary external websites. This is possible because the confirmation_url parameter is not validated, enabling attackers to craft malicious links for phishing and credential harvesting attacks. Organizations usi [truncated]
CVE-2026-56330 is a medium-severity open redirect vulnerability in Capgo before version 12.128.2. The vulnerability affects the stripe_portal and stripe_checkout endpoints, which accept unvalidated callbackUrl, successUrl, and cancelUrl parameters. This allows authenticated attackers to craft malicious billing URLs that can redirect users to attacker-controlled domains for phishing and credential harvesti [truncated]
CVE-2026-56325 is a low-severity vulnerability in Capgo before 12.128.2. The issue arises from the use of ILIKE pattern matching instead of exact matching for app_id lookup in the preview subdomain resolver. This allows attackers to create apps with app_ids differing by one character at underscore positions, potentially causing unintended pattern matches. This could break preview functionality for legitim [truncated]
CVE-2026-56319 is a medium-severity information disclosure vulnerability in Capgo before 12.128.2. The vulnerability exists in the GET /statistics/app/:app_id endpoint, enabling app-limited API keys to differentiate between existing and non-existent sibling app IDs through distinct error responses. This issue compromises tenant isolation, allowing attackers to enumerate real app IDs outside their permitte [truncated]
CVE-2026-56282 is a medium-severity information disclosure vulnerability in Capgo before version 12.128.2. The vulnerability exists in the unauthenticated /replication endpoint, exposing internal PostgreSQL replication telemetry, including slot names and WAL LSN positions. This allows attackers to retrieve sensitive infrastructure details without authentication, which can be used for reconnaissance purpos [truncated]
CVE-2026-56228 is a medium-severity vulnerability in Capgo, a mobile app development platform. An authenticated organization administrator can set an extremely large numeric value as the minimum password length, causing an organization-wide account lockout and application-level denial of service. This issue was reported on June 20, 2026, and patched in version 12.128.2. The vulnerability has a CVSS score [truncated]
CVE-2026-56227 is a medium-severity server-side request forgery (SSRF) vulnerability in Capgo versions before 12.128.2. The issue arises from inadequate webhook URL validation, permitting organization admins to configure webhooks pointing to localhost or 127.0.0.1. When triggered, the backend performs outbound requests to these addresses, disclosing error responses to users. Defenders should assess their [truncated]
CVE-2026-56215 is a high-severity vulnerability in Capgo, a platform that allows authenticated users to modify their public.users.email field to arbitrary addresses. This issue enables attackers to pre-position their account with a victim's corporate SSO email, causing the provision-user endpoint to merge the victim's SSO identity into the attacker-controlled account.
CVE-2026-53868 is a high-severity denial of service vulnerability in Capgo, a platform that allows attackers to register accounts using arbitrary email addresses without verification. By initiating deletion, attackers can lock emails in a pending deletion state, permanently locking legitimate users out of the platform for 30 days. This vulnerability has a CVSS score of 8.7 and is considered HIGH severity.