Vulnerabilidades em capgo
83 resultadosAnálise Vexday
Capgo possui apenas 1 CVE registrado na base, publicado recentemente (últimos 90 dias), relacionado a questões de link/path traversal (CWE-59), sem evidência de exploração ativa no cenário de ameaças. O risco atual é baixo, mas a recência da vulnerabilidade exige validação da aplicabilidade ao seu ambiente.
CVE-2026-56243HIGHCapgo - Hashed API Key Enforcement Bypass via PostgREST/RLS PlaneEPSS 0.4%CVE-2026-56312MEDIUMCapgo - Account Creation Before CAPTCHA Validation in accept_invitation EndpointEPSS 0.4%CVE-2026-56229HIGHCapgo - Cross-App Build Job Access via app_id/job_id Mismatch in /build/status and /build/logsEPSS 0.4%CVE-2026-56255MEDIUMCapgo - Denial of Service via Unlimited Demo App CreationEPSS 0.4%CVE-2026-56241HIGHCapgo - RBAC Demotion Privilege Retention via Stale org_users.user_rightEPSS 0.4%CVE-2026-56311MEDIUMCapgo - Unauthenticated Cross-Tenant Disclosure via get_current_plan_max_org RPCEPSS 0.4%CVE-2026-56249HIGHCapgo - Unauthorized Channel Overwrite and Ownership Takeover via POST /channel Name CollisionEPSS 0.4%CVE-2026-56318MEDIUMCapgo - Information Disclosure via /private/validate_password_compliance EndpointEPSS 0.4%CVE-2026-56327MEDIUMCapgo - Unauthenticated Organization Existence Oracle via public.invite_user_to_org RPCEPSS 0.4%CVE-2026-56309MEDIUMCapgo - Plan Bypass via Unrestricted Attachment Upload EndpointEPSS 0.4%CVE-2026-56213MEDIUMCapgo - Unauthenticated Cross-Tenant Metrics Poisoning via upsert_version_meta RPCEPSS 0.4%CVE-2026-56328HIGHCapgo - Integrity Issue in Release Routing via Multiple Public ChannelsEPSS 0.3%CVE-2026-56220HIGHCapgo - Unauthorized Manifest Insertion via Read-Only Org MemberEPSS 0.3%CVE-2026-56302MEDIUMCapgo - Unsecured Supabase Images Bucket via Missing Row Level SecurityEPSS 0.3%CVE-2026-56239HIGHCapgo - Privilege Escalation via SECURITY DEFINER Function apply_usage_overageEPSS 0.3%CVE-2026-56306MEDIUMCapgo - Subkey Enforcement Bypass via x-limited-key-id Header ParsingEPSS 0.3%CVE-2026-56218MEDIUMCapgo - EXIF Metadata Exposure via Image UploadEPSS 0.3%CVE-2026-56331MEDIUMCapgo - Improper Error Handling in Accept Invitation Endpoint via Invalid Magic StringEPSS 0.3%CVE-2026-56336MEDIUMCapgo - Information Disclosure via Unauthenticated SSO check-domain EndpointEPSS 0.3%CVE-2026-56212MEDIUMCapgo - Improper 2FA Enforcement Logic via Team Security SettingsEPSS 0.3%