VulnSea

capgo.app vulnerabilities

CVEs whose affected-version data names the capgo.app package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-88864Critical· 9.1PoC
1w ago

Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST

Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST. A holder of an ordinary Capgo full API key can insert a row with status='active' and enforce_sso=true, bypassin…

AbyssalCap-go · capgo.appEPSS 0.26%via NVD
CVE-2026-88863High· 8.1
1w ago

capgo.app (npm package `capgo`) through version 12.207.1 does not compare the caller's role rank against the requested role in the validateInvite() function of supabase/functions/_backend/private/invite_new_user_to_org.ts

capgo.app (npm package `capgo`) through version 12.207.1 does not compare the caller's role rank against the requested role in the validateInvite() function of supabase/functions/_backend/private/invite_new_user_to_org.ts. The POST /priv…

TwilightCap-go · capgo.appEPSS 0.22%via NVD
CVE-2026-88862High· 8.8PoC
1w ago

Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id header

Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id header. checkKeyByIdPg() in supabase/functions/_backend/utils/hono_middleware.ts resolves the attacker-supplied num…

MidnightCap-go · capgo.appEPSS 0.31%via NVD
CVE-2026-88861High· 8.3PoC
1w ago

Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication)

Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication). The Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC…

MidnightCap-go · capgo.appEPSS 0.29%via NVD
CVE-2026-88860Medium· 6.3
1w ago

Capgo fails to clean up channel permission overrides when a user's last organization role binding is deleted, leaving stale overrides active

Capgo fails to clean up channel permission overrides when a user's last organization role binding is deleted, leaving stale overrides active. Attackers can retain channel-specific permissions after their base RBAC access has been revoked…

SunlitCap-go · capgo.appEPSS 0.16%via NVD
capgo.app vulnerabilities (CVEs) · VulnSea