Vulnerabilities in Capgo

83 results
Vexday analysis

Capgo apresenta 82 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando exposição recente e significativa. Embora nenhuma esteja sob ataque ativo no momento, apenas 2 são críticas, a fraqueza dominante é exposição de informações (CWE-200), sugerindo vazamento de dados como padrão de risco principal. A concentração de divulgações recentes demanda monitoramento contínuo para detecção precoce de exploração em larga escala.

CVE-2026-56299MEDIUMCapgo - Denial of Service via Unauthenticated OPTIONS Request to /build/upload EndpointEPSS 0.7%CVE-2026-56323HIGHCapgo - Unauthenticated Channel Enumeration and App Oracle via GET /channel_selfEPSS 0.6%CVE-2026-56228MEDIUMCapgo - Denial of Service via Improper Password Policy Length ValidationEPSS 0.5%CVE-2026-56324HIGHCapgo - Rate Limit Bypass via User-Controlled device_id ParameterEPSS 0.5%CVE-2026-56214HIGHCapgo - Unauthenticated Organization Enumeration and Billing Status Disclosure via Supabase RPCEPSS 0.5%CVE-2026-56321MEDIUMCapgo - Missing Authentication Middleware on GET /private/role_bindings EndpointEPSS 0.5%CVE-2026-56233HIGHCapgo - SSRF and Privilege Escalation via Path Traversal in Builder Upload ProxyEPSS 0.5%CVE-2026-56251HIGHCapgo - Privilege Escalation via Broken Row Level Security in org_usersEPSS 0.4%CVE-2026-56216HIGHCapgo - Scope Escalation via API Key Creation in /functions/v1/apikeyEPSS 0.4%CVE-2026-56242HIGHCapgo - Unauthenticated API Key Validity Oracle and User Identity Disclosure via get_identity_apikey_only RPCEPSS 0.4%CVE-2026-56314HIGHCapgo - Deleted Bundle Selection via Missing Deletion Filter in /updates EndpointEPSS 0.4%CVE-2026-56253HIGHCapgo - Unauthenticated Organization Member Email Disclosure via get_org_members RPCEPSS 0.4%CVE-2026-56079HIGHCapgo - Cross-Tenant Authorization Bypass via PostgREST Webhook AccessEPSS 0.4%CVE-2026-56282MEDIUMCapgo - Information Disclosure via Unauthenticated /replication EndpointEPSS 0.4%CVE-2026-56215HIGHCapgo - Account Merge via Poisoned public.users.email in SSO ProvisioningEPSS 0.4%CVE-2026-56229HIGHCapgo - Cross-App Build Job Access via app_id/job_id Mismatch in /build/status and /build/logsEPSS 0.4%CVE-2026-56255MEDIUMCapgo - Denial of Service via Unlimited Demo App CreationEPSS 0.4%CVE-2026-56238HIGHCapgo - Unauthenticated Information Disclosure via PostgREST global_stats EndpointEPSS 0.4%CVE-2026-56311MEDIUMCapgo - Unauthenticated Cross-Tenant Disclosure via get_current_plan_max_org RPCEPSS 0.4%CVE-2026-56305HIGHCapgo - Authentication Bypass in Password Change via Missing Current Password ValidationEPSS 0.4%