---
id: CVE-2026-56254
title: >-
  In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end
  encryption scheme distributes the private key to each device that downloads
  the app
summary: >-
  In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end
  encryption scheme distributes the private key to each device that downloads
  the app. Because the public key can be derived from the private key, an
  attacker perfo…
severity: high
cvss: 7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L'
cwe:
  - CWE-320
vendor: capacitor-updater
product: capacitor-updater
affected:
  - capacitor-updater < 12.128.2
published: '2026-07-10'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:21.793'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-56254'
references:
  - url: 'https://github.com/Cap-go/capgo/security/advisories/GHSA-j2f4-4pfc-p8rx'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/capacitor-updater-end-to-end-encryption-bypass-via-private-key-distribution
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-07-10T15:17:07.705805Z'
epss: 0.00195
epssPercentile: 0.08449
ingestedAt: '2026-10-08T16:52:14.697Z'
---

## Overview

In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app. Because the public key can be derived from the private key, an attacker performing a man-in-the-middle attack or compromising the Capgo server can create a validly signed update bundle and cause devices to install an update not produced by the original app maker.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
