Executive brief
Capgo, a platform for managing app builds and updates, suffered from a configuration error that prevented build status information from being correctly saved. This issue caused automated build requests to appear stuck in a 'pending' state indefinitely, even if they had actually failed. As a result, developers and administrators could not see accurate build statuses or error logs in their dashboards, hindering troubleshooting and operational visibility.
Technical details
A missing UPDATE Row-Level Security (RLS) policy in the Supabase-backed database for Capgo prevented the persistence of builder status updates. While the `/build/status` endpoint could retrieve real-time status, the backend failed to update the `public.build_requests` table because the API-key and anonymous roles lacked the necessary permissions. This resulted in rows remaining in a 'pending' state with `null` values for `last_error`. An attacker or a standard user could trigger builds that appear to never complete, leading to data inconsistency between the build system and the management dashboard. The issue was resolved in version 12.128.2 by correctly defining the RLS policies.
Affected products
- Capgo Capgo < 12.128.2
Timeline
- 2026-03-03: advisory: GitHub Security Advisory published
- 2026-06-30: disclosed: NVD publication date