Executive brief
Capgo, a platform for managing over-the-air (OTA) updates for mobile applications, contains a security flaw that allows users with limited API access to bypass encryption requirements. An attacker with an app-scoped API key can downgrade encrypted software update bundles to an unencrypted state, even if the organization has policies in place to prevent this. This undermines the security of the update delivery process and could allow for the distribution of unprotected application code.
Technical details
A policy bypass vulnerability exists in Capgo's backend due to improper enforcement of encryption invariants during database updates. While the system uses a database trigger to ensure bundles are encrypted upon insertion (INSERT), it fails to apply the same logic during updates (UPDATE) via PostgREST. An attacker possessing an app-scoped API key with 'all' permissions can issue a direct PostgREST PATCH request to the 'app_versions' table to clear the 'session_key' and 'key_id' fields. This effectively downgrades an existing encrypted bundle to an unencrypted state, bypassing organization-level 'enforce_encrypted_bundles' policies. The issue is resolved in version 12.128.2 by applying the encryption invariant check to both INSERT and UPDATE operations.
Affected products
- Capgo Capgo < 12.128.2
Timeline
- 2026-05-07: advisory: GitHub Security Advisory published
- 2026-07-08: disclosed: NVD publication date