CVE-2026-100619: Incorrect Privilege Assignment in Cap-go capgo.app
Capgo (capgo.app) blocks direct user inserts into the public.manifest table with a RESTRICTIVE row-level security policy, but that restriction can be bypassed indirectly. A principal holding an app-scoped upload/write/all API key (upload+ rights) or an authenticated user with write+ rights on an app can update public.app_versions.manifest on a version whose storage_provider is 'r2-direct', which is not covered by the bundle content-lock check. The on_version_update async worker trusts record.manifest and, using the service-role Supabase client, inserts the attacker-controlled file_name, file_hash, and s3_path into public.manifest before clearing app_versions.manifest. When a channel points to the crafted version, the /updates endpoint returns the service-role-created manifest entry as a client-facing download_url, enabling OTA manifest poisoning through a trusted async worker path. All versions are affected; no patch was available at the time of publication.
AI Analysis
Technical Summary
Cap-go's capgo.app implements a restrictive row-level security policy to block direct user inserts into the public.manifest table. However, this restriction can be bypassed indirectly by principals holding app-scoped upload/write/all API keys or authenticated users with write+ rights on an app. These users can update public.app_versions.manifest on versions with storage_provider set to 'r2-direct', which bypasses the bundle content-lock check. An asynchronous on_version_update worker then trusts the record.manifest and, using a service-role Supabase client, inserts attacker-controlled file_name, file_hash, and s3_path into public.manifest before clearing app_versions.manifest. When a channel points to this crafted version, the /updates endpoint returns the malicious manifest entry as a client-facing download_url, enabling over-the-air manifest poisoning through a trusted async worker path. All versions of capgo.app are affected. The service is cloud-hosted and a patch is available.
Potential Impact
An attacker with upload/write API keys or write+ rights can inject malicious entries into the update manifest table, causing the /updates endpoint to serve attacker-controlled download URLs. This compromises the integrity of over-the-air updates by poisoning manifests, potentially leading to clients downloading malicious files. The vulnerability bypasses intended row-level security and content-lock checks, undermining update trustworthiness.
Mitigation Recommendations
As capgo.app is a cloud-hosted service, the vendor manages remediation server-side. A patch is available to address this vulnerability. Users should verify with the vendor advisory that their instance is updated. No additional user action is required if the service is fully managed and patched.
CVE-2026-100619: Incorrect Privilege Assignment in Cap-go capgo.app
Description
Capgo (capgo.app) blocks direct user inserts into the public.manifest table with a RESTRICTIVE row-level security policy, but that restriction can be bypassed indirectly. A principal holding an app-scoped upload/write/all API key (upload+ rights) or an authenticated user with write+ rights on an app can update public.app_versions.manifest on a version whose storage_provider is 'r2-direct', which is not covered by the bundle content-lock check. The on_version_update async worker trusts record.manifest and, using the service-role Supabase client, inserts the attacker-controlled file_name, file_hash, and s3_path into public.manifest before clearing app_versions.manifest. When a channel points to the crafted version, the /updates endpoint returns the service-role-created manifest entry as a client-facing download_url, enabling OTA manifest poisoning through a trusted async worker path. All versions are affected; no patch was available at the time of publication.
CVSS v4.0
Score 8.7high
Affected software
Cap-go
capgo.app
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Cap-go's capgo.app implements a restrictive row-level security policy to block direct user inserts into the public.manifest table. However, this restriction can be bypassed indirectly by principals holding app-scoped upload/write/all API keys or authenticated users with write+ rights on an app. These users can update public.app_versions.manifest on versions with storage_provider set to 'r2-direct', which bypasses the bundle content-lock check. An asynchronous on_version_update worker then trusts the record.manifest and, using a service-role Supabase client, inserts attacker-controlled file_name, file_hash, and s3_path into public.manifest before clearing app_versions.manifest. When a channel points to this crafted version, the /updates endpoint returns the malicious manifest entry as a client-facing download_url, enabling over-the-air manifest poisoning through a trusted async worker path. All versions of capgo.app are affected. The service is cloud-hosted and a patch is available.
Potential Impact
An attacker with upload/write API keys or write+ rights can inject malicious entries into the update manifest table, causing the /updates endpoint to serve attacker-controlled download URLs. This compromises the integrity of over-the-air updates by poisoning manifests, potentially leading to clients downloading malicious files. The vulnerability bypasses intended row-level security and content-lock checks, undermining update trustworthiness.
Mitigation Recommendations
As capgo.app is a cloud-hosted service, the vendor manages remediation server-side. A patch is available to address this vulnerability. Users should verify with the vendor advisory that their instance is updated. No additional user action is required if the service is fully managed and patched.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-26T02:31:07.602Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Is Cloud Service
- true
Threat ID: 6ab7c9a1f7a7c5410652fd05
Added to database: 09/26/2026, 13:33:21 UTC
Last enriched: 09/26/2026, 14:18:37 UTC
Last updated: 09/27/2026, 04:31:33 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.