Executive brief
Cap is an open-source screen recording application similar to Loom. An authenticated user can post comments on private videos belonging to other users by manipulating the request, potentially embarrassing video owners and triggering unwanted notifications. This breaks the confidentiality of private recordings.
Technical details
The vulnerability is a broken access control (IDOR) flaw in the POST /api/video/comment endpoint. An authenticated user can post comments on private videos by supplying an arbitrary videoId in the request body, bypassing authorization checks that should verify the user has access to view the target video. The attack requires authentication but no additional user interaction. Attackers can inject arbitrary comments, trigger comment notification emails to video owners, and enumerate valid video IDs by analyzing response differences. A patch was released in commit 1b812d8 requiring canView access verification before allowing comment submission.
Affected products
- CapSoftware Cap v0.3.1
Timeline
- 2026-08-11: disclosed
- 2026: patched: Fix released in commit 1b812d8