Executive brief
Capgo, a platform for managing app updates and deployments, contained a security flaw where certain API keys could bypass intended restrictions. An attacker with a standard 'write' API key could modify sensitive channel settings that were supposed to be permanent or protected, such as whether a channel is public or if it allows emulators. This could lead to unauthorized changes in how software updates are distributed to users or the exposure of private development channels.
Technical details
An authorization bypass exists in Capgo versions prior to 12.128.2 due to a flaw in the 'public.noupdate()' immutability trigger. The trigger, designed to prevent modifications to sensitive channel fields, contains a logic error that returns early (skipping checks) if 'auth.uid()' is NULL. Because API-key authenticated requests via PostgREST result in a NULL authentication ID, the immutability enforcement is bypassed. Simultaneously, the Row Level Security (RLS) UPDATE policy on the 'public.channels' table permits write-scoped API keys to perform updates. An authenticated attacker with a write-scoped API key can exploit this to modify protected attributes such as 'public', 'allow_emulator', and other security flags. The issue is resolved in version 12.128.2.
Affected products
- Capgo Capgo < 12.128.2
Timeline
- 2026-05-07: advisory: Vendor advisory published on GitHub
- 2026-07-10: disclosed: CVE published to NVD