CVE-2026-56254High· 7.0▾ TwilightIn @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app. Because the public key can be derived from the private key, an attacker perfo…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app. Because the public key can be derived from the private key, an attacker performing a man-in-the-middle attack or compromising the Capgo server can create a validly signed update bundle and cause devices to install an update not produced by the original app maker.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105392High· 7.3A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12
CVE-2026-102241Low· 2.7A vulnerability was determined in Netcore NAP930 0.1.241010.141410
CVE-2026-90510High· 8.3A security vulnerability has been detected in dromara orion-visor up to 2.5.7
CVE-2026-86241Medium· 4.3A weakness has been identified in liufee FeehiCMS up to 2.1.1
CVE-2025-11609Low· 3.7A flaw has been found in code-projects Hospital Management System 1.0
CVE-2025-14651Low· 3.7A vulnerability has been found in MartialBE one-hub up to 0.14.27