Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
23.688 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.4) | 0.11% | — | Google Fuse-archiveAI | 28/9/2026 | 29/9/2026 | In Google fuse-archive versions prior to 1.24, an attacker who can prepend a directory to PATH or write a malicious binary to an attacker-controlled or writable directory appearing in PATH can hijack the execution pathway. This allows the attacker to execute arbitrary local code under the security context of the user… | |
| Analizada | Media (5.1) | 0.19% | — | Gohugo Hugo | 26/9/2026 | 30/9/2026 | Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media type are rendered without escaping raw HTML: Org export blocks and @@html:...@@ snippets pass HTML through unescaped, resulting in cross-site scripting (XSS) in the generated site. An attacker who can… | |
| Analizada | Alta (8.6) | 0.14% | — | Gohugo Hugo | 26/9/2026 | 30/9/2026 | Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-literal deny rule that allows attackers to bypass restrictions. Attackers can use mixed-case URL schemes in resources.GetRemote calls to fetch from restricted IP addresses like localhost. | |
| Analizada | Alta (8.7) | 0.42% | — | Gohugo Hugo | 26/9/2026 | 29/9/2026 | Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopped at the mount root itself, so a theme or module checked into themes/ (or a vendored module) could contain a symlink at a mount root (for example themes/mytheme/assets -> /some/dir/outside). Files… | |
| Analizada | Media (5.1) | 0.17% | — | Gohugo Hugo | 26/9/2026 | 29/9/2026 | Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does not escape the `lineAnchors` option before passing it to Chroma, which writes the value verbatim into the `id` and `href` attributes of the generated line-number markup. A crafted `lineAnchors` value… | |
| Analizada | Alta (8.7) | 0.35% | — | Gohugo Hugo | 26/9/2026 | 30/9/2026 | Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.js permission model to restrict file system reads to the project directory and configured mounts. Because the Node.js permission model validates only the lexical path and follows symbolic links that… | |
| Aplazada | Alta (7) | 0.28% | — | CapgoAI | 26/9/2026 | 5/10/2026 | Capgo (capgo.app backend) before 12.127.5 contains an authorization flaw in the PATCH /private/role_bindings/:binding_id endpoint. The handler verifies that the newly assigned role's priority rank does not exceed the caller's own rank, but — unlike the DELETE handler — it never checks the rank of the role currently… | |
| Aplazada | Alta (8.7) | 0.20% | — | CapgoAI | 26/9/2026 | 28/9/2026 | capgo.app before 12.128.12 fails to enforce an organization's API key expiration policy when creating app-scoped API keys. In the POST /apikey endpoint, requests that supply app_id but omit org_id, limited_to_orgs, and expires_at resolve the target app and scope the key to it, but never add the app's owner… | |
| Aplazada | Alta (7.2) | 0.29% | — | CapgoAI | 26/9/2026 | 30/9/2026 | Capgo (Cap-go/capgo.app) server backend Supabase functions contain an incorrect authorization flaw in the API-key bundle promotion path. The PUT /bundle endpoint, available to "all" and "write" API keys, dispatches to setChannel, which authorizes with checkPermission(c, 'channel.promote_bundle', { appId: body.app_id… | |
| Aplazada | Media (5.3) | 0.18% | — | CapgoAI | 26/9/2026 | 28/9/2026 | capgo through 12.128.2 contains an insecure direct object reference vulnerability in the PUT /app/:appId endpoint that accepts attacker-controlled icon storage paths. Authenticated users can supply arbitrary paths in the private images bucket and obtain service-role-signed URLs valid for 7 days to read cross-tenant… | |
| Aplazada | Alta (8.7) | 0.25% | — | CapgoAI | 26/9/2026 | 30/9/2026 | Capgo (capgo.app) exposes a native build TUS upload proxy (supabase/functions/_backend/public/build/upload.ts) that authorizes a caller against a single build job identified by the supplied builder_job_id and validates only that job's stored upload_path, but then forwards the user-controlled TUS resource suffix taken… | |
| Aplazada | Media (5.3) | 0.22% | — | CapgoAI | 26/9/2026 | 5/10/2026 | Capgo.app before 12.264.5 does not enforce upload expiry or build lifecycle state in the /build/upload/:jobId TUS proxy endpoint. When a native build request is created, an upload_expires_at timestamp (one hour) and a 'pending' status are stored in build_requests, but the upload proxy loads only app_id, owner_org,… | |
| Aplazada | Alta (8.7) | 0.32% | — | CapgoAI | 26/9/2026 | 30/9/2026 | Capgo (capgo.app) exposes the legacy membership table public.org_users directly through Supabase PostgREST. The table's row-level security policies "Allow org admin to insert" and "Allow org admin to update" only verify that the caller has admin rights in the target organization (public.check_min_rights('admin',… | |
| Aplazada | Alta (8.7) | 0.33% | — | CapgoAI | 26/9/2026 | 28/9/2026 | capgo.app through 12.129.0 fails to verify deletion status when serving cached bundle artifacts from the public file read endpoint. Unauthenticated attackers can download deleted bundles using cached URLs and trigger restoration of deleted objects into R2 storage on cache hits. | |
| Aplazada | Media (5.3) | 0.22% | — | CapgoAI | 26/9/2026 | 30/9/2026 | Capgo (capgo.app) contains an incomplete access-control/content-lock enforcement issue affecting all versions; no patch is available at the time of publication. The `enforce_encrypted_bundle_trigger` / `check_encrypted_bundle_on_insert` content lock in supabase/schemas/prod.sql exempts `app_versions` rows whose… | |
| Aplazada | Media (5.1) | 0.25% | — | Capgo CLIAI | 26/9/2026 | 5/10/2026 | Capgo CLI (npm package @capgo/cli) through 7.98.2 is affected by an over-permissioned service account in its Android onboarding flow. When onboarding via Google OAuth, the CLI invites the generated Google Play service account with the account-wide Play Console permission CAN_MANAGE_DRAFT_APPS_GLOBAL (passed as… | |
| Aplazada | Alta (8.7) | 0.32% | — | CapgoAI | 26/9/2026 | 30/9/2026 | Capgo (capgo.app) blocks direct user inserts into the public.manifest table with a RESTRICTIVE row-level security policy, but that restriction can be bypassed indirectly. A principal holding an app-scoped upload/write/all API key (upload+ rights) or an authenticated user with write+ rights on an app can update… | |
| Aplazada | Alta (8.7) | 0.21% | — | CapgoAI | 26/9/2026 | 30/9/2026 | Capgo (capgo.app) is affected by an authorization flaw in the app icon update path. The PUT /app/:id endpoint accepts a user-controlled `icon` value, normalizes it, and stores it in public.apps.icon_url without verifying that the image path belongs to the target app's own image namespace (e.g.… | |
| Aplazada | Alta (8.7) | 0.30% | — | CapgoAI | 26/9/2026 | 30/9/2026 | Cap-go capgo.app fails to validate that principals in channel_permission_overrides belong to the organization, allowing authenticated app/org admins to grant channel permissions to non-member users. Attackers with admin privileges can insert override rows with arbitrary external user UUIDs to grant channel-scoped… | |
| Aplazada | Alta (7) | 0.27% | — | CapgoAI | 26/9/2026 | 5/10/2026 | capgo.app is an over-the-air update platform for Capacitor apps. In all versions prior to a fix, the row-level security UPDATE policy on the public.orgs table permits an organization admin (a user holding org.update_settings) to update the entire row, including the internal billing pointer column customer_id. The… | |
| Aplazada | Alta (8.7) | 0.31% | — | CapgoAI | 26/9/2026 | 28/9/2026 | Cap-go capgo.app before 12.267.1 fails to validate target API key privilege during rotation, allowing an apikey_manager to rotate a higher-privileged org_super_admin sibling key and recover its plaintext credential. Attackers with apikey_manager role can enumerate same-owner API keys, rotate a stronger sibling through… | |
| Aplazada | Alta (8.7) | 0.32% | — | CapgoAI | 26/9/2026 | 28/9/2026 | Capgo before 12.244.1 contains a cross-tenant integrity vulnerability in the metadata-cleaning worker that trusts image object keys from mutable database rows without validating ownership. An authenticated attacker can place a victim tenant's image key in a row they control, causing the service-role worker to download… | |
| Aplazada | Media (6) | 0.21% | — | CapgoAI | 26/9/2026 | 30/9/2026 | capgo.app is an over-the-air (OTA) update platform for Capacitor apps. In all versions up to and including the current release (no patch available at time of publication), the `transfer_app()` database function transfers an app, its channels, versions and related records to a destination organization without deleting… | |
| Aplazada | Alta (8.6) | 0.34% | — | CapgoAI | 26/9/2026 | 30/9/2026 | Capgo (capgo.app) through version 12.261.0 contains an incomplete access-control fix for the public.sso_providers table. Migration 20260826100000_sso_providers_block_direct_active_insert.sql installs a BEFORE UPDATE guard (enforce_sso_provider_client_update_guard()) that freezes only the dns_verified_at, domain,… | |
| Aplazada | Alta (7.1) | 0.22% | — | CapgoAI | 26/9/2026 | 30/9/2026 | Capgo (capgo.app backend, versions ≤ 12.261.0) improperly restricts which roles the apikey_manager organization role may bind to newly created API keys. When an authenticated user holding only apikey_manager (permissions org.manage_apikeys and org.read) calls POST /apikey with a JWT session, the only checks applied… |