Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Capgo — Vulnerabilities & Security Advisories 83

Browse all 83 CVE security advisories affecting Capgo. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates security vulnerabilities associated with the Capgo vendor, focusing on weaknesses classified under the Common Weakness Enumeration (CWE) standard. It compiles a comprehensive list of known security issues, tracking data from early reports through the most recent advisories published by the vendor. The content covers various risk levels and software components, ensuring a holistic view of the security posture. Users can utilize this resource to track a vendor's advisories over time, observing how quickly issues are acknowledged and resolved. The page allows security professionals and developers to understand a specific weakness class as it applies to Capgo’s ecosystem, identifying patterns in recurring flaws or specific architectural risks. Additionally, individuals can look up a product's vulnerability history to assess the long-term stability and maintenance quality of the software. By centralizing this information, the page serves as a critical reference for risk assessment, helping stakeholders make informed decisions about software procurement, patching priorities, and compatibility checks. This structured approach eliminates the need to scour multiple sources for disjointed data, providing a single point of truth for Capgo-related security concerns.

Top products by Capgo: Capgo cli
Low2026-07-15
Unauthenticated org existence oracle via public Supabase RPC public.rescind_invitation(email, org_id) (SECURITY DEFINER)
High2026-07-12
Bug Report: No Password Verification During Email Change — Email Changed Without Confirming Current Password · Advisory
Low2026-07-12
Unauthenticated SSO check-domain Endpoint Exposes Internal org_id and provider_id · Advisory · Cap-go/capgo · GitHub
Medium2026-07-12
SSO Prelink Cross-Org Account Disruption - Enterprise Admin Can Delete Password Identity of Users in Foreign Orgs · Advi
High2026-07-12
RBAC demotion does not clear org_users.user_right - demoted super_admin retains access to delete_non_compliant_bundles a
High2026-07-11
Exhausted or expired usage credit grants keep plugin plan_valid true, bypassing billing gates on /updates, /stats, /chan
High2026-07-11
Unauthenticated SECURITY DEFINER RPC find_apikey_by_value Exposes API Key Metadata to anon · Advisory · Cap-go/capgo · G
Medium2026-07-10
Cross-tenant preview namespace collision via non-bijective __ → . decoding causes preview misrouting / denial of preview
High2026-07-10
Incident Report: No Password Confirmation While Changing New Password — Critical Account Security Weakness · Advisory ·
High2026-07-09
🛡️ Bug Report: HTML Injection Leading to Open Redirection · Advisory · Cap-go/capgo · GitHub
High2026-07-08
Upload-scoped API key can retarget app_versions.r2_path and trigger deletion of another R2 bundle object · Advisory · Ca
High2026-07-08
Scoped API key can perform cross-org destructive actions by inheriting owner-user permissions · Advisory · Cap-go/capgo
Medium2026-07-02
Multiple same-platform public channels can coexist, while unnamed /updates selects a single implicit winner · Advisory ·
High2026-07-02
Org admins can assign org-level RBAC roles at app scope, including to pending invitees, leading to end-to-end privilege
Medium2026-07-02
500 Internal Server Error on /private/accept_invitation when magic_invite_string is invalid (tmp_users “single JSON obje
Medium2026-07-02
Unauthenticated Supabase RPCs expose API key validity + user/org permission oracles (get_user_id, get_org_perm_for_apike
Medium2026-07-02
Authenticated org admin can bypass /organization security-setting validation via direct browser-side public.orgs updates
Medium2026-07-02
Bug Report: Account Deletion Without Password Confirmation — No Re-Authentication Required to Delete Account · Advisory
High2026-07-02
High Severity BOLA/IDOR: x-limited-key-id enables cross-tenant limited-key adoption in middlewareKey() · Advisory · Cap-
High2026-07-02
SSRF and Privilege Escalation in Builder Upload Proxy via Path Traversal · Advisory · Cap-go/capgo · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with Capgo. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.