Executive brief
capgo is a platform for managing mobile app deployments and updates. The platform's app icon upload endpoint fails to validate that authenticated users can only access their own files, allowing attackers to obtain temporary download URLs for other users' private images—including avatars, organization logos, and app icons—without proper authorization. These signed URLs remain valid for 7 days and can be used to download sensitive files without further authentication.
Technical details
The PUT /app/:appId endpoint accepts an attacker-controlled icon storage path and mints 7-day signed URLs using the Supabase service-role client, which bypasses row-level security policies. The normalizeImagePath function performs only string formatting, not path validation, allowing authenticated attackers to request signed URLs for arbitrary paths in the private images bucket (user_id/filename, org/org_id/logo/filename, org/org_id/app_id/icon). Path enumeration is feasible because org IDs are visible to members and user/app IDs are often publicly known.
Affected products
- Cap-go capgo through 12.128.2
Timeline
- 2026-09-26: disclosed