Executive brief
Capgo, a platform for managing over-the-air (OTA) updates for mobile applications, contains a security flaw in its update delivery system. An unauthorized person can use this flaw to discover private internal testing channels and view sensitive deployment details, such as app version numbers and platform configurations. This could allow competitors or malicious actors to monitor a company's internal development progress and release cycles.
Technical details
An information disclosure vulnerability exists in the Capgo /updates endpoint due to improper order of operations during request processing. The 'defaultChannel' parameter is resolved by name before privacy and self-assignment restrictions are enforced. An unauthenticated remote attacker can perform a side-channel attack by probing channel names; valid private channels return distinct error messages (e.g., platform-specific denials or version upgrade warnings) compared to nonexistent channels. This allows for the enumeration of private channel names and the extraction of sensitive metadata, including assigned bundle versions and platform-specific configuration states. The issue is fixed in version 12.128.2.
Affected products
- Capgo Capgo < 12.128.2
Timeline
- 2026-05-07: advisory: GitHub Security Advisory published
- 2026-06-23: disclosed: CVE published and NVD record created