Executive brief
Capgo, a platform for managing app updates and deployments, contained a security flaw that allowed unauthorized individuals to view sensitive internal information. By sending specific requests to the service, an attacker could identify private development channels, confirm the existence of specific applications, and see the billing or subscription status of customers. This information could be used to plan more targeted attacks or gather competitive intelligence on Capgo users.
Technical details
An information disclosure vulnerability exists in Capgo's `/functions/v1/channel_self` endpoint due to a lack of authentication and authorization checks. The GET handler fails to call `checkPermission()` and does not require a `device_id` or API key, allowing any remote attacker to query the endpoint with arbitrary `app_id` parameters. This enables the enumeration of non-public internal rollout channels (e.g., dev, beta), confirmation of valid application IDs across different tenants, and the leakage of billing/subscription status through distinct error responses like 'need_plan_upgrade'. The issue was addressed in version 12.128.2 by implementing stricter access controls and normalizing responses.
Affected products
- Capgo Capgo < 12.128.2
Timeline
- 2026-02-10: advisory: GitHub Security Advisory published
- 2026-06-22: disclosed: CVE published and NVD record created