Executive brief
Capgo, an over-the-air (OTA) update service for mobile applications, contained a flaw that allowed low-privileged, read-only organization members to modify update metadata. By injecting malicious entries into the update manifest, an internal attacker could redirect user devices to download unauthorized or malicious assets. This could lead to the delivery of compromised application code to end-users, potentially impacting the security and integrity of the mobile apps relying on the service.
Technical details
An authorization bypass exists in Capgo's Supabase Row Level Security (RLS) policy for the 'public.manifest' table. The INSERT policy incorrectly validated only organization membership rather than verifying write or upload permissions. An authenticated attacker with read-only access to an organization can use Supabase PostgREST to insert rows into the manifest table with arbitrary 's3_path' values. These malicious entries are subsequently trusted by the unauthenticated '/updates' endpoint and served to mobile devices as valid OTA manifest download URLs, enabling metadata poisoning and the delivery of malicious application assets. The issue was resolved in version 12.128.2.
Affected products
- Capgo Capgo < 12.128.2
Timeline
- 2026-05-07: advisory: GitHub Security Advisory published
- 2026-07-08: disclosed: NVD publication date