CVE-2026-100624: Insufficient Session Expiration in Cap-go capgo.app
Capgo.app versions before 12.264.5 have a vulnerability in the /build/upload/:jobId TUS proxy endpoint where upload expiry and build lifecycle state are not enforced. Authenticated users with app.build_native permission can continue uploading to a build session after its expiry or after the build phase has ended, unless the builder service independently blocks the request. This issue is fixed in version 12.264.5.
AI Analysis
Technical Summary
The vulnerability in Capgo.app prior to version 12.264.5 involves insufficient session expiration enforcement in the /build/upload/:jobId TUS proxy endpoint. Although an upload_expires_at timestamp and a 'pending' status are stored when a native build request is created, the proxy endpoint only verifies app.build_native permission and certain identifiers without checking upload expiry or build lifecycle state. Consequently, an authenticated caller with the required permission can continue to write to the upload session beyond the intended expiry time or after the build has progressed past the upload phase, potentially leading to unauthorized or unintended build uploads. The issue is resolved in version 12.264.5.
Potential Impact
An authenticated user with app.build_native permission can continue uploading data to a build session after the session's intended expiration or after the build phase has ended. This could lead to unauthorized modifications or uploads to builds beyond their expected lifecycle. The impact is limited to users with the specific permission and does not involve privilege escalation or remote unauthenticated access. No known exploits are reported in the wild.
Mitigation Recommendations
Upgrade Capgo.app to version 12.264.5 or later, where this issue is fixed. Until then, ensure that the builder service independently enforces upload expiry and build lifecycle state to prevent unauthorized uploads beyond session expiration.
CVE-2026-100624: Insufficient Session Expiration in Cap-go capgo.app
Description
Capgo.app versions before 12.264.5 have a vulnerability in the /build/upload/:jobId TUS proxy endpoint where upload expiry and build lifecycle state are not enforced. Authenticated users with app.build_native permission can continue uploading to a build session after its expiry or after the build phase has ended, unless the builder service independently blocks the request. This issue is fixed in version 12.264.5.
CVSS v4.0
Score 5.3medium
Affected software
Cap-go
capgo.app
pkg:github/cap-go/capgo.appRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Capgo.app prior to version 12.264.5 involves insufficient session expiration enforcement in the /build/upload/:jobId TUS proxy endpoint. Although an upload_expires_at timestamp and a 'pending' status are stored when a native build request is created, the proxy endpoint only verifies app.build_native permission and certain identifiers without checking upload expiry or build lifecycle state. Consequently, an authenticated caller with the required permission can continue to write to the upload session beyond the intended expiry time or after the build has progressed past the upload phase, potentially leading to unauthorized or unintended build uploads. The issue is resolved in version 12.264.5.
Potential Impact
An authenticated user with app.build_native permission can continue uploading data to a build session after the session's intended expiration or after the build phase has ended. This could lead to unauthorized modifications or uploads to builds beyond their expected lifecycle. The impact is limited to users with the specific permission and does not involve privilege escalation or remote unauthenticated access. No known exploits are reported in the wild.
Mitigation Recommendations
Upgrade Capgo.app to version 12.264.5 or later, where this issue is fixed. Until then, ensure that the builder service independently enforces upload expiry and build lifecycle state to prevent unauthorized uploads beyond session expiration.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-26T02:31:07.602Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab7c9a3f7a7c5410652fd0d
Added to database: 09/26/2026, 13:33:23 UTC
Last enriched: 09/26/2026, 14:18:24 UTC
Last updated: 09/26/2026, 14:47:52 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.