Cap-go has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was September 2026 with 5. The median CVSS is 8.3 (high), with 1 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.3
- Publish → KEV
- —
- Last 90 days
- 5 prev 0
Worst active — by depth score
CVE-2026-88864Critical· 9.1Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST62CVE-2026-88862High· 8.8Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id header60CVE-2026-88861High· 8.3Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication)58CVE-2026-88863High· 8.1capgo.app (npm package `capgo`) through version 12.207.1 does not compare the caller's role rank against the requested role in the validateInvite() function of supabase/functions/_backend/private/invite_new_user_to_org.ts45CVE-2026-88860Medium· 6.3Capgo fails to clean up channel permission overrides when a user's last organization role binding is deleted, leaving stale overrides active35
Cap-go vulnerabilities
CVEs affecting Cap-go, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-88864Critical· 9.1PoCCapgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST
Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST. A holder of an ordinary Capgo full API key can insert a row with status='active' and enforce_sso=true, bypassin…
CVE-2026-88863High· 8.1capgo.app (npm package `capgo`) through version 12.207.1 does not compare the caller's role rank against the requested role in the validateInvite() function of supabase/functions/_backend/private/invite_new_user_to_org.ts
capgo.app (npm package `capgo`) through version 12.207.1 does not compare the caller's role rank against the requested role in the validateInvite() function of supabase/functions/_backend/private/invite_new_user_to_org.ts. The POST /priv…
CVE-2026-88862High· 8.8PoCCapgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id header
Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id header. checkKeyByIdPg() in supabase/functions/_backend/utils/hono_middleware.ts resolves the attacker-supplied num…
CVE-2026-88861High· 8.3PoCCapgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication)
Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication). The Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC…
CVE-2026-88860Medium· 6.3Capgo fails to clean up channel permission overrides when a user's last organization role binding is deleted, leaving stale overrides active
Capgo fails to clean up channel permission overrides when a user's last organization role binding is deleted, leaving stale overrides active. Attackers can retain channel-specific permissions after their base RBAC access has been revoked…