Executive brief
Capgo, a platform for managing live updates for mobile applications, contained a flaw that allowed multiple 'public' update channels to exist for the same app and platform simultaneously. This creates a situation where the system's behavior becomes unpredictable, as devices requesting updates without a specific channel name would receive a version from a single 'hidden' winner channel. An authorized manager could exploit this to silently manipulate which software version users receive, undermining the integrity and reliability of the app's release process.
Technical details
A release routing integrity vulnerability exists in Capgo due to improper enforcement of channel uniqueness and incomplete normalization. The system allowed the creation of multiple channels marked as 'public' for the same app_id and platform because the database upsert logic only checked for conflicts on (app_id, name) and the normalization trigger only fired on UPDATE events, not INSERTs. When a client makes an unnamed /updates request (without a defaultChannel), the backend resolves the update using a query with a limit(1) clause but no specific ordering, causing it to select an implicit 'winner' from the multiple public channels. An authenticated attacker with app or channel management permissions can exploit this to create an ambiguous state and silently influence which bundle clients receive. This was fixed in version 12.128.2.
Affected products
- Capgo Capgo < 12.128.2
Timeline
- 2026-05-07: advisory: GitHub Security Advisory published
- 2026-06-30: disclosed: NVD publication date