Executive brief
Capgo is a mobile app deployment platform that provides over-the-air (OTA) updates to end users. An authenticated user with limited API key management permissions can create API keys with elevated deployment capabilities they do not personally hold, allowing them to push arbitrary JavaScript updates to all users of an organization's apps without having direct upload or promotion rights.
Technical details
The apikey_manager role lacks a check verifying that the caller holds the permissions being assigned to a new API key. Only three guards exist: an org.manage_apikeys permission check, an incomplete deny-list of restricted role names, and a priority-rank comparison. The deny-list omits four deploy roles (app_developer, app_uploader, channel_developer, channel_uploader) and apikey_manager's priority rank (78) exceeds their ranks, allowing the rank check to pass. An authenticated apikey_manager can exploit this to mint API keys with OTA deploy capabilities and push arbitrary updates to all end users.
Affected products
- Capgo capgo.app backend ≤ 12.261.0
Timeline
- 2026-09-26: disclosed
- 2026-09-26: advisory: GHSA-2x4j-p4pr-fvp8 published