Executive brief
Capgo is a platform for managing and deploying mobile applications. The vulnerability allows an attacker with a standard API key to bypass security controls and create fraudulent single sign-on (SSO) providers, enabling them to force arbitrary domains to require SSO authentication without proper verification. This disrupts normal user login and could prevent legitimate users from accessing applications.
Technical details
The vulnerability is an improper access control flaw (CWE-284) in Capgo's Supabase backend. The public.sso_providers table is directly writable via Supabase PostgREST using a standard API key, allowing an attacker to insert rows with status='active' and enforce_sso=true. This bypasses the intended backend SSO provisioning workflow located in supabase/functions/_backend/private/sso/providers.ts, which includes Enterprise plan checks, DNS TXT domain-ownership verification, and Supabase Management API validation. The unauthenticated login preflight endpoint /private/sso/check-domain trusts the local sso_providers table state without verifying its origin, causing it to report {"has_sso": true, "enforce_sso": true} for unverified domains. Attack requires only a valid Capgo full API key (no authentication bypass needed to obtain one) and network access to Supabase PostgREST. An attacker can disrupt login for any domain and assert control over SSO enforcement. No patch was available at the time of disclosure, affecting all versions.
Affected products
- Capgo capgo.app all
Timeline
- 2026-09-10: disclosed
- 2026-08-27: advisory: GitHub security advisory GHSA-xg7v-83qv-qfff published