CVE-2026-100613Medium· 5.3▾ Sunlitcapgo.app is an over-the-air (OTA) update platform for Capacitor apps. In all versions up to and including the current release (no patch available at time of publication), the `transfer_app()` database function transfers an app, its chan…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
capgo.app is an over-the-air (OTA) update platform for Capacitor apps. In all versions up to and including the current release (no patch available at time of publication), the transfer_app() database function transfers an app, its channels, versions and related records to a destination organization without deleting or revalidating existing rows in channel_permission_overrides. As a result, a user who legitimately held a channel permission override while a member of the source organization retains that override after the transfer, even though they have no membership and no RBAC binding in the destination organization. Using their own authenticated JWT against the PostgREST API, such a former member can modify the destination-owned channel to point at a different bundle, causing the /updates endpoint to serve an attacker-selected application version to devices. The previously proposed fix for GHSA-626c-p6fq-3whq (PR #3093), which validates organization membership when an override is created or updated, does not remove overrides that became stale as a result of an app transfer.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-100616Medium· 5.5capgo.app is an over-the-air update platform for Capacitor apps
CVE-2026-100629Medium· 5.5Capgo (capgo.app backend) before 12.127.5 contains an authorization flaw in the PATCH /private/role_bindings/:binding_id endpoint
CVE-2026-100623High· 8.8Capgo (capgo.app) exposes the legacy membership table public.org_users directly through Supabase PostgREST
CVE-2026-100628Medium· 4.3capgo.app before 12.128.12 fails to enforce an organization's API key expiration policy when creating app-scoped API keys
CVE-2026-88860Medium· 6.3Capgo fails to clean up channel permission overrides when a user's last organization role binding is deleted, leaving stale overrides active
CVE-2026-88862High· 8.8Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id header