Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3040▲ 560 respecto a la semana anterior
Críticas / altas1452▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
126 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7) | 0.28% | — | CapgoAI | 26/9/2026 | 28/9/2026 | Capgo (capgo.app backend) before 12.127.5 contains an authorization flaw in the PATCH /private/role_bindings/:binding_id endpoint. The handler verifies that the newly assigned role's priority rank does not exceed the caller's own rank, but — unlike the DELETE handler — it never checks the rank of the role currently… | |
| Aplazada | Alta (8.7) | 0.20% | — | CapgoAI | 26/9/2026 | 28/9/2026 | capgo.app before 12.128.12 fails to enforce an organization's API key expiration policy when creating app-scoped API keys. In the POST /apikey endpoint, requests that supply app_id but omit org_id, limited_to_orgs, and expires_at resolve the target app and scope the key to it, but never add the app's owner… | |
| Aplazada | Alta (7.2) | 0.29% | — | CapgoAI | 26/9/2026 | 30/9/2026 | Capgo (Cap-go/capgo.app) server backend Supabase functions contain an incorrect authorization flaw in the API-key bundle promotion path. The PUT /bundle endpoint, available to "all" and "write" API keys, dispatches to setChannel, which authorizes with checkPermission(c, 'channel.promote_bundle', { appId: body.app_id… | |
| Aplazada | Media (5.3) | 0.18% | — | CapgoAI | 26/9/2026 | 28/9/2026 | capgo through 12.128.2 contains an insecure direct object reference vulnerability in the PUT /app/:appId endpoint that accepts attacker-controlled icon storage paths. Authenticated users can supply arbitrary paths in the private images bucket and obtain service-role-signed URLs valid for 7 days to read cross-tenant… | |
| Aplazada | Alta (8.7) | 0.25% | — | CapgoAI | 26/9/2026 | 30/9/2026 | Capgo (capgo.app) exposes a native build TUS upload proxy (supabase/functions/_backend/public/build/upload.ts) that authorizes a caller against a single build job identified by the supplied builder_job_id and validates only that job's stored upload_path, but then forwards the user-controlled TUS resource suffix taken… | |
| Aplazada | Media (5.3) | 0.22% | — | CapgoAI | 26/9/2026 | 28/9/2026 | Capgo.app before 12.264.5 does not enforce upload expiry or build lifecycle state in the /build/upload/:jobId TUS proxy endpoint. When a native build request is created, an upload_expires_at timestamp (one hour) and a 'pending' status are stored in build_requests, but the upload proxy loads only app_id, owner_org,… | |
| Aplazada | Alta (8.7) | 0.32% | — | CapgoAI | 26/9/2026 | 30/9/2026 | Capgo (capgo.app) exposes the legacy membership table public.org_users directly through Supabase PostgREST. The table's row-level security policies "Allow org admin to insert" and "Allow org admin to update" only verify that the caller has admin rights in the target organization (public.check_min_rights('admin',… | |
| Aplazada | Alta (8.7) | 0.33% | — | CapgoAI | 26/9/2026 | 28/9/2026 | capgo.app through 12.129.0 fails to verify deletion status when serving cached bundle artifacts from the public file read endpoint. Unauthenticated attackers can download deleted bundles using cached URLs and trigger restoration of deleted objects into R2 storage on cache hits. | |
| Aplazada | Media (5.3) | 0.22% | — | CapgoAI | 26/9/2026 | 30/9/2026 | Capgo (capgo.app) contains an incomplete access-control/content-lock enforcement issue affecting all versions; no patch is available at the time of publication. The `enforce_encrypted_bundle_trigger` / `check_encrypted_bundle_on_insert` content lock in supabase/schemas/prod.sql exempts `app_versions` rows whose… | |
| Aplazada | Media (5.1) | 0.25% | — | Capgo CLIAI | 26/9/2026 | 28/9/2026 | Capgo CLI (npm package @capgo/cli) through 7.98.2 is affected by an over-permissioned service account in its Android onboarding flow. When onboarding via Google OAuth, the CLI invites the generated Google Play service account with the account-wide Play Console permission CAN_MANAGE_DRAFT_APPS_GLOBAL (passed as… | |
| Aplazada | Alta (8.7) | 0.32% | — | CapgoAI | 26/9/2026 | 30/9/2026 | Capgo (capgo.app) blocks direct user inserts into the public.manifest table with a RESTRICTIVE row-level security policy, but that restriction can be bypassed indirectly. A principal holding an app-scoped upload/write/all API key (upload+ rights) or an authenticated user with write+ rights on an app can update… | |
| Aplazada | Alta (8.7) | 0.21% | — | CapgoAI | 26/9/2026 | 30/9/2026 | Capgo (capgo.app) is affected by an authorization flaw in the app icon update path. The PUT /app/:id endpoint accepts a user-controlled `icon` value, normalizes it, and stores it in public.apps.icon_url without verifying that the image path belongs to the target app's own image namespace (e.g.… | |
| Aplazada | Alta (8.7) | 0.30% | — | CapgoAI | 26/9/2026 | 30/9/2026 | Cap-go capgo.app fails to validate that principals in channel_permission_overrides belong to the organization, allowing authenticated app/org admins to grant channel permissions to non-member users. Attackers with admin privileges can insert override rows with arbitrary external user UUIDs to grant channel-scoped… | |
| Aplazada | Alta (7) | 0.27% | — | CapgoAI | 26/9/2026 | 30/9/2026 | capgo.app is an over-the-air update platform for Capacitor apps. In all versions prior to a fix, the row-level security UPDATE policy on the public.orgs table permits an organization admin (a user holding org.update_settings) to update the entire row, including the internal billing pointer column customer_id. The… | |
| Aplazada | Alta (8.7) | 0.31% | — | CapgoAI | 26/9/2026 | 28/9/2026 | Cap-go capgo.app before 12.267.1 fails to validate target API key privilege during rotation, allowing an apikey_manager to rotate a higher-privileged org_super_admin sibling key and recover its plaintext credential. Attackers with apikey_manager role can enumerate same-owner API keys, rotate a stronger sibling through… | |
| Aplazada | Alta (8.7) | 0.32% | — | CapgoAI | 26/9/2026 | 28/9/2026 | Capgo before 12.244.1 contains a cross-tenant integrity vulnerability in the metadata-cleaning worker that trusts image object keys from mutable database rows without validating ownership. An authenticated attacker can place a victim tenant's image key in a row they control, causing the service-role worker to download… | |
| Aplazada | Media (6) | 0.21% | — | CapgoAI | 26/9/2026 | 30/9/2026 | capgo.app is an over-the-air (OTA) update platform for Capacitor apps. In all versions up to and including the current release (no patch available at time of publication), the `transfer_app()` database function transfers an app, its channels, versions and related records to a destination organization without deleting… | |
| Aplazada | Alta (8.6) | 0.34% | — | CapgoAI | 26/9/2026 | 30/9/2026 | Capgo (capgo.app) through version 12.261.0 contains an incomplete access-control fix for the public.sso_providers table. Migration 20260826100000_sso_providers_block_direct_active_insert.sql installs a BEFORE UPDATE guard (enforce_sso_provider_client_update_guard()) that freezes only the dns_verified_at, domain,… | |
| Aplazada | Alta (7.1) | 0.22% | — | CapgoAI | 26/9/2026 | 30/9/2026 | Capgo (capgo.app backend, versions ≤ 12.261.0) improperly restricts which roles the apikey_manager organization role may bind to newly created API keys. When an authenticated user holding only apikey_manager (permissions org.manage_apikeys and org.read) calls POST /apikey with a JWT session, the only checks applied… | |
| Aplazada | Alta (8.6) | 0.39% | — | CapgoAI | 10/9/2026 | 10/9/2026 | capgo.app (npm package `capgo`) through version 12.207.1 does not compare the caller's role rank against the requested role in the validateInvite() function of supabase/functions/_backend/private/invite_new_user_to_org.ts. The POST /private/invite_new_user_to_org endpoint only requires the org.update_user_roles… | |
| Aplazada | Crítica (9.3) | 0.37% | — | CapgoAISupabaseAISupabase PostgrestAI | 10/9/2026 | 30/9/2026 | Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST. A holder of an ordinary Capgo full API key can insert a row with status='active' and enforce_sso=true, bypassing the intended backend SSO provisioning route… | |
| Aplazada | Alta (8.7) | 0.44% | — | CapgoAI | 10/9/2026 | 30/9/2026 | Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id header. checkKeyByIdPg() in supabase/functions/_backend/utils/hono_middleware.ts resolves the attacker-supplied numeric API key ID using only the key ID, its expiration state, and the… | |
| Aplazada | Alta (8.7) | 0.52% | — | CapgoAISupabaseAI | 10/9/2026 | 30/9/2026 | Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication). The Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC permissions even when the account has a verified MFA factor that has not been… | |
| Aplazada | Crítica (9.3) | 0.27% | — | CapgoAI | 10/9/2026 | 30/9/2026 | Capgo fails to clean up channel permission overrides when a user's last organization role binding is deleted, leaving stale overrides active. Attackers can retain channel-specific permissions after their base RBAC access has been revoked to perform unauthorized actions like changing production OTA versions. | |
| Aplazada | Alta (8.7) | 0.46% | — | CapgoAISupabase PostgrestAI | 15/7/2026 | 15/7/2026 | Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST SECURITY DEFINER RPC function public.rescind_invitation that allows unauthenticated attackers to enumerate organization existence. The function returns distinct error messages (NO_ORG vs NO_RIGHTS) when… |