Executive brief
Capgo, a platform for managing app updates, contained a security flaw where certain internal functions were accessible to the public without a password. An attacker could use these functions to check if stolen API keys are valid, identify specific users, and discover private application IDs. This information makes leaked credentials much more dangerous and could lead to further unauthorized access to customer data and application settings.
Technical details
Capgo versions prior to 12.128.2 contain two Supabase PostgREST RPC functions, 'get_user_id' and 'get_org_perm_for_apikey', which are configured as SECURITY DEFINER and granted execution permissions to the 'anon' role. This allows unauthenticated remote attackers using a public publishable key to perform API key validation and user UUID disclosure. Specifically, 'get_user_id' returns a user's UUID when provided with a valid API key, while 'get_org_perm_for_apikey' allows for the enumeration of application IDs and the retrieval of organization permission strings. These oracles significantly increase the utility of leaked credentials and facilitate user and application enumeration. The issue was addressed in version 12.128.2 by restricting access to these functions.
Affected products
- Capgo Capgo < 12.128.2
Timeline
- 2026-05-07: advisory: Vendor advisory published on GitHub
- 2026-06-30: disclosed: CVE published and NVD record created