Junglewise Threat Intelligence

CVE-2026-56334: Capgo missing UPDATE RLS policy in build_requests table

CVE-2026-56334 · Severity: medium · CVSS 4.3 · Published 2026-06-30

Technologies: Capgo. Vendors: Capgo.

Executive brief

Capgo, a platform for managing app builds and updates, suffered from a configuration error that prevented build status information from being correctly saved. This issue caused automated build requests to appear stuck in a 'pending' state indefinitely, even if they had actually failed. As a result, developers and administrators could not see accurate build statuses or error logs in their dashboards, hindering troubleshooting and operational visibility.

Technical details

A missing UPDATE Row-Level Security (RLS) policy in the Supabase-backed database for Capgo prevented the persistence of builder status updates. While the `/build/status` endpoint could retrieve real-time status, the backend failed to update the `public.build_requests` table because the API-key and anonymous roles lacked the necessary permissions. This resulted in rows remaining in a 'pending' state with `null` values for `last_error`. An attacker or a standard user could trigger builds that appear to never complete, leading to data inconsistency between the build system and the management dashboard. The issue was resolved in version 12.128.2 by correctly defining the RLS policies.

Affected products

  • Capgo Capgo < 12.128.2

Timeline

  • 2026-03-03: advisory: GitHub Security Advisory published
  • 2026-06-30: disclosed: NVD publication date

References

Related threats