Executive brief
Cap-go, a platform for managing app updates, contained a security flaw where restricted API keys could access data they weren't supposed to see. Specifically, an API key limited to one organization could be used to view member details—such as email addresses and user roles—of other organizations. This could lead to unauthorized data exposure and a breach of privacy between different business accounts using the service.
Technical details
An authorization bypass exists in Cap-go's backend API due to improper enforcement of API key scopes. While the 'GET /organization/members' endpoint performs standard RBAC checks, it fails to validate the 'limited_to_orgs' restriction associated with specific API keys. An authenticated attacker possessing an API key restricted to a specific organization can successfully query the membership data of other organizations they have general access to, bypassing the intended scope limitation. This exposure includes sensitive fields such as user IDs (uid), email addresses, profile image URLs, and roles. The issue was resolved in version 12.128.2 by implementing explicit organization-scope enforcement.
Affected products
- Cap-go capgo < 12.128.2
Timeline
- 2026-05-07: advisory: Vendor advisory published on GitHub
- 2026-06-24: disclosed: CVE published and NVD record created