Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-100627 — Capgo bundle promotion API channel RBAC deny override bypass

Capgo (Cap-go/capgo.app) server backend Supabase functions contain an incorrect authorization flaw in the API-key bundle promotion path. The PUT /bundle endpoint, available to "all" and "write" API k…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
5.3 MEDIUM
CVE-2026-100626 — capgo through 12.128.2 IDOR via PUT /app icon endpoint

capgo through 12.128.2 contains an insecure direct object reference vulnerability in the PUT /app/:appId endpoint that accepts attacker-controlled icon storage paths. Authenticated users can supply a…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.7 HIGH
CVE-2026-100625 — Capgo Build Upload Proxy Authorization Bypass via TUS Resource

Capgo (capgo.app) exposes a native build TUS upload proxy (supabase/functions/_backend/public/build/upload.ts) that authorizes a caller against a single build job identified by the supplied builder_j…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
5.4 MEDIUM
CVE-2026-100624 — Capgo.app before 12.264.5 Upload Expiry Bypass via build upload

Capgo.app before 12.264.5 does not enforce upload expiry or build lifecycle state in the /build/upload/:jobId TUS proxy endpoint. When a native build request is created, an upload_expires_at timestam…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.8 HIGH
CVE-2026-100623 — Capgo Authentication Bypass via Direct PostgREST org_users Table Write

Capgo (capgo.app) exposes the legacy membership table public.org_users directly through Supabase PostgREST. The table's row-level security policies "Allow org admin to insert" and "Allow org admin to…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.7 HIGH
CVE-2026-100622 — capgo.app through 12.129.0 Cache Restoration of Deleted Bundles

capgo.app through 12.129.0 fails to verify deletion status when serving cached bundle artifacts from the public file read endpoint. Unauthenticated attackers can download deleted bundles using cached…

Remote | Information Disclosure
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
5.3 MEDIUM
CVE-2026-100621 — capgo.app Content-Lock Bypass via r2-direct Bundle Mutation

Capgo (capgo.app) contains an incomplete access-control/content-lock enforcement issue affecting all versions; no patch is available at the time of publication. The `enforce_encrypted_bundle_trigger`…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
5.1 MEDIUM
CVE-2026-100620 — Capgo CLI through 7.98.2 Excessive Permissions via Overpermissioned Play Console Service …

Capgo CLI (npm package @capgo/cli) through 7.98.2 is affected by an over-permissioned service account in its Android onboarding flow. When onboarding via Google OAuth, the CLI invites the generated G…

Remote | Misconfiguration
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.8 HIGH
CVE-2026-100619 — Capgo OTA Manifest Poisoning via app_versions.manifest Bypass

Capgo (capgo.app) blocks direct user inserts into the public.manifest table with a RESTRICTIVE row-level security policy, but that restriction can be bypassed indirectly. A principal holding an app-s…

Remote | Misconfiguration
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.7 HIGH
CVE-2026-100618 — Capgo App Icon Update Privilege Escalation via Service-Role Worker

Capgo (capgo.app) is affected by an authorization flaw in the app icon update path. The PUT /app/:id endpoint accepts a user-controlled `icon` value, normalizes it, and stores it in public.apps.icon_…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.8 HIGH
CVE-2026-100617 — Cap-go capgo.app Authorization Bypass via channel_permission_overrides

Cap-go capgo.app fails to validate that principals in channel_permission_overrides belong to the organization, allowing authenticated app/org admins to grant channel permissions to non-member users. …

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.0 HIGH
CVE-2026-100616 — capgo.app Authentication Bypass via PostgREST customer_id Mutation

capgo.app is an over-the-air update platform for Capacitor apps. In all versions prior to a fix, the row-level security UPDATE policy on the public.orgs table permits an organization admin (a user ho…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.8 HIGH
CVE-2026-100615 — Cap-go capgo.app before 12.267.1 Privilege Escalation via API Key Rotation

Cap-go capgo.app before 12.267.1 fails to validate target API key privilege during rotation, allowing an apikey_manager to rotate a higher-privileged org_super_admin sibling key and recover its plain…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.8 HIGH
CVE-2026-100614 — Capgo before 12.244.1 Cross-Tenant Image Overwrite via Metadata Worker

Capgo before 12.244.1 contains a cross-tenant integrity vulnerability in the metadata-cleaning worker that trusts image object keys from mutable database rows without validating ownership. An authent…

Remote | Misconfiguration
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
6.0 MEDIUM
CVE-2026-100613 — capgo.app Authorization Bypass via Stale Channel Permission Overrides

capgo.app is an over-the-air (OTA) update platform for Capacitor apps. In all versions up to and including the current release (no patch available at time of publication), the `transfer_app()` databa…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.6 HIGH
CVE-2026-100612 — Capgo SSO Provider ID Authentication Bypass via Incomplete Migration

Capgo (capgo.app) through version 12.261.0 contains an incomplete access-control fix for the public.sso_providers table. Migration 20260826100000_sso_providers_block_direct_active_insert.sql installs…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.1 HIGH
CVE-2026-100611 — Capgo apikey_manager Role Privilege Escalation via Incomplete Role Deny-list

Capgo (capgo.app backend, versions ≤ 12.261.0) improperly restricts which roles the apikey_manager organization role may bind to newly created API keys. When an authenticated user holding only apikey…

Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.7 HIGH
CVE-2026-100610 — Flowise through 3.1.4 Missing Authorization via upsert-history

Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id and PATCH /api/v1/upsert-history without route-level permission checks, and the backing service performs no workspace or ownership validat…

flowise | Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
7.6 HIGH
CVE-2026-100609 — Flowise through 3.1.4 Insecure Direct Object Reference via Credential

Flowise (npm packages `flowise` and `flowise-components`) through 3.1.4 looks up credentials by ID without filtering on the requesting user's workspace (findOneBy({ id: credentialId }) with no worksp…

flowise | Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
8.7 HIGH
CVE-2026-100608 — Flowise through 3.1.4 Authorization Bypass via BullMQ Dashboard

Flowise through 3.1.4 does not enforce authorization on the BullMQ admin dashboard. When the server runs in queue mode with the dashboard enabled and not in cloud mode (MODE=queue, ENABLE_BULLMQ_DASH…

flowise | Remote | Authorization
Sep 26, 2026 Sep 26, 2026
Sep 26, 2026
Sep 26, 2026
Showing 20 of 14674 Results