Executive brief
Capgo, a platform for managing app updates, contained a security flaw where internal database health data was publicly accessible. An unauthorized person could view technical details about how the system synchronizes data, including internal server names and database error messages. While this does not directly expose user passwords, it provides attackers with a roadmap of the company's internal infrastructure that could be used to plan more sophisticated attacks.
Technical details
An information disclosure vulnerability exists in Capgo's backend due to a lack of authentication middleware on the `/replication` endpoint. The route, defined in `supabase/functions/_backend/public/replication.ts`, only implements CORS headers and fails to restrict access to authorized users. A remote, unauthenticated attacker can query this endpoint to retrieve PostgreSQL replication slot names, Write-Ahead Log (WAL) LSN positions (such as `confirmed_flush_lsn`), and detailed database error strings. This telemetry reveals internal naming conventions, provider regions, and infrastructure health, facilitating reconnaissance. The issue is resolved in version 12.128.2 by restricting the endpoint or minimizing the returned data.
Affected products
- Capgo Capgo < 12.128.2
Timeline
- 2026-03-03: advisory: GitHub Security Advisory published
- 2026-06-20: disclosed: NVD publication and CVE assignment