Executive brief
Capgo, a platform for managing app updates and deployments, contained a flaw in its permission management system. An organization administrator could assign high-level permissions to a user before they even joined the organization, and these permissions would incorrectly persist after the user accepted their invitation. This could allow a low-privileged user to gain full administrative control over specific applications, potentially leading to unauthorized data access or service disruption.
Technical details
A privilege escalation vulnerability exists in Capgo's RBAC system due to insufficient validation in the role assignment endpoint (`role_bindings.ts`). The system fails to verify that a role's `scope_type` (e.g., organization-wide) matches the requested binding scope (e.g., app-specific). Furthermore, the system allows these roles to be assigned to pending invitees. Because the authorization resolver (`rbac_has_permission`) trusts the `role_id` without verifying scope compatibility, and the invitation acceptance process fails to clear these malformed bindings, a low-privilege user can inherit high-level permissions (such as `org_super_admin`) restricted to a specific application. This allows the attacker to perform unauthorized actions via direct Row-Level Security (RLS) updates. The issue is patched in version 12.128.2.
Affected products
- Capgo Capgo before 12.128.2
Timeline
- 2026-05-07: advisory: GitHub Security Advisory published
- 2026-06-30: disclosed: NVD publication date