{"id":"CVE-2026-56254","title":"In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app","summary":"In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app. Because the public key can be derived from the private key, an attacker perfo…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L","cwe":["CWE-320"],"vendor":"capacitor-updater","product":"capacitor-updater","affected":["capacitor-updater < 12.128.2"],"published":"2026-07-10","updated":"2026-10-08","sourceUpdated":"2026-10-08T16:17:21.793","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-56254","references":[{"url":"https://github.com/Cap-go/capgo/security/advisories/GHSA-j2f4-4pfc-p8rx","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/capacitor-updater-end-to-end-encryption-bypass-via-private-key-distribution","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-07-10T15:17:07.705805Z"},"epss":0.00195,"epssPercentile":0.08449,"ingestedAt":"2026-10-08T16:52:14.697Z","slug":"CVE-2026-56254","body":"## Overview\n\nIn @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app. Because the public key can be derived from the private key, an attacker performing a man-in-the-middle attack or compromising the Capgo server can create a validly signed update bundle and cause devices to install an update not produced by the original app maker.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}