Executive brief
Capgo, a platform for managing mobile app updates and builds, contained a security flaw that allowed users to view build information for applications they did not own. By using a valid API key for one application and providing a specific build ID from another, an attacker could access sensitive build logs and metadata. This could lead to the exposure of proprietary code details, environment configurations, or embedded credentials.
Technical details
An authorization bypass (CWE-639) exists in Capgo's /build/status and /build/logs endpoints due to insufficient validation of the relationship between the provided app_id and job_id. The application performs permission checks against the user-supplied app_id but retrieves build data using only the job_id. An authenticated attacker with a limited API key can bypass restrictions by providing an authorized app_id alongside a job_id belonging to a different, unauthorized application. This allows the retrieval of sensitive build logs, metadata, and potentially credentials from other applications within the same environment. The issue is resolved in version 12.128.2 by verifying that the job_id belongs to the authorized app_id before returning data.
Affected products
- Capgo Capgo < 12.128.2
Timeline
- 2026-02-10: advisory: Vendor advisory published on GitHub
- 2026-06-21: disclosed: CVE published and NVD record created