CVE-2026-100613: Incorrect Authorization in Cap-go capgo.app
capgo.app is an over-the-air (OTA) update platform for Capacitor apps. In all versions up to and including the current release (no patch available at time of publication), the `transfer_app()` database function transfers an app, its channels, versions and related records to a destination organization without deleting or revalidating existing rows in `channel_permission_overrides`. As a result, a user who legitimately held a channel permission override while a member of the source organization retains that override after the transfer, even though they have no membership and no RBAC binding in the destination organization. Using their own authenticated JWT against the PostgREST API, such a former member can modify the destination-owned channel to point at a different bundle, causing the /updates endpoint to serve an attacker-selected application version to devices. The previously proposed fix for GHSA-626c-p6fq-3whq (PR #3093), which validates organization membership when an override is created or updated, does not remove overrides that became stale as a result of an app transfer.
AI Analysis
Technical Summary
The vulnerability in capgo.app involves the transfer_app() database function failing to delete or revalidate existing channel_permission_overrides during an app transfer between organizations. Consequently, users who had channel permission overrides in the source organization retain those overrides after the transfer, even though they lack membership or RBAC bindings in the destination organization. By authenticating with their own JWT via the PostgREST API, these former members can modify destination-owned channels to point to different bundles, causing the /updates endpoint to serve potentially malicious application versions. A prior fix addressed validation when creating or updating overrides but did not remove stale overrides resulting from app transfers. No patch is currently available.
Potential Impact
An attacker who was previously a member of the source organization but no longer has membership in the destination organization can retain channel permission overrides after an app transfer. This allows them to modify the destination organization's channel to serve attacker-selected app versions to devices. This could lead to unauthorized code execution or deployment of malicious updates via the OTA update mechanism.
Mitigation Recommendations
No official patch or fix is available at this time. Users should monitor vendor advisories for updates. Since the vulnerability involves stale permission overrides after app transfers, organizations should consider manual review and cleanup of channel permission overrides following transfers as a temporary mitigation until an official fix is released.
CVE-2026-100613: Incorrect Authorization in Cap-go capgo.app
Description
capgo.app is an over-the-air (OTA) update platform for Capacitor apps. In all versions up to and including the current release (no patch available at time of publication), the `transfer_app()` database function transfers an app, its channels, versions and related records to a destination organization without deleting or revalidating existing rows in `channel_permission_overrides`. As a result, a user who legitimately held a channel permission override while a member of the source organization retains that override after the transfer, even though they have no membership and no RBAC binding in the destination organization. Using their own authenticated JWT against the PostgREST API, such a former member can modify the destination-owned channel to point at a different bundle, causing the /updates endpoint to serve an attacker-selected application version to devices. The previously proposed fix for GHSA-626c-p6fq-3whq (PR #3093), which validates organization membership when an override is created or updated, does not remove overrides that became stale as a result of an app transfer.
CVSS v4.0
Score 6.0medium
Affected software
Cap-go
capgo.app
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in capgo.app involves the transfer_app() database function failing to delete or revalidate existing channel_permission_overrides during an app transfer between organizations. Consequently, users who had channel permission overrides in the source organization retain those overrides after the transfer, even though they lack membership or RBAC bindings in the destination organization. By authenticating with their own JWT via the PostgREST API, these former members can modify destination-owned channels to point to different bundles, causing the /updates endpoint to serve potentially malicious application versions. A prior fix addressed validation when creating or updating overrides but did not remove stale overrides resulting from app transfers. No patch is currently available.
Potential Impact
An attacker who was previously a member of the source organization but no longer has membership in the destination organization can retain channel permission overrides after an app transfer. This allows them to modify the destination organization's channel to serve attacker-selected app versions to devices. This could lead to unauthorized code execution or deployment of malicious updates via the OTA update mechanism.
Mitigation Recommendations
No official patch or fix is available at this time. Users should monitor vendor advisories for updates. Since the vulnerability involves stale permission overrides after app transfers, organizations should consider manual review and cleanup of channel permission overrides following transfers as a temporary mitigation until an official fix is released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-26T02:30:34.353Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab7c9a1f7a7c5410652fcfe
Added to database: 09/26/2026, 13:33:21 UTC
Last enriched: 09/26/2026, 14:18:58 UTC
Last updated: 09/27/2026, 02:21:08 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.