Executive brief
Capgo, a tool for managing app updates and assets, contained a security misconfiguration in its image storage system. An unauthenticated attacker could remotely access, delete, or modify application icons stored on the platform. This flaw also allowed for the exposure of sensitive internal identifiers, such as application and user IDs, potentially impacting customer privacy and service appearance.
Technical details
A vulnerability exists in Capgo versions prior to 12.128.2 due to missing Row Level Security (RLS) controls on a Supabase-hosted images bucket. This bucket is used to store application icons. Because no access controls were enforced, unauthenticated remote attackers could perform CRUD (Create, Read, Update, Delete) operations on the stored assets via the network. Beyond the integrity risk of icon deletion or replacement, the flaw allows for the unauthorized disclosure of sensitive metadata, specifically app IDs and user IDs. The issue is resolved in version 12.128.2.
Affected products
- Capgo Capgo < 12.128.2
Timeline
- 2026-02-10: advisory: Initial GHSA advisory published
- 2026-06-24: disclosed: CVE published to NVD dataset