Skip to main content

CVE-2026-100625: Unintended Proxy or Intermediary ('Confused Deputy') in Cap-go capgo.app

0
High
VulnerabilityCVE-2026-100625cvecve-2026-100625
Published: 09/26/2026 (09/26/2026, 13:23:03 UTC)
Source: CVE Database V5
Vendor/Project: Cap-go
Product: capgo.app

Description

CVE-2026-100625 is a high-severity vulnerability in Capgo (capgo.app) involving an unintended proxy or 'confused deputy' issue. The native build TUS upload proxy authorizes callers based on a single build job ID and validates only that job's upload path. However, it forwards a user-controlled resource suffix to the builder service while injecting a privileged API key, without binding the suffix to the authorized job. This allows an attacker with valid API keys and permissions for one application to write to the upload resource of another job if the resource suffix is known, potentially corrupting build artifacts. No patch was available at the time of advisory publication, and all versions are affected.

CVSS v4.0

Score 8.7high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
None
Vuln. Availability
None
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected software

Cap-go

capgo.app

GitHub Actionsmore threats →ai
cap-go/capgo.app
pkg:github/cap-go/capgo.app
Affected versions
*

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/26/2026, 14:18:08 UTC

Technical Analysis

Capgo's native build TUS upload proxy (supabase/functions/_backend/public/build/upload.ts) authorizes a caller against a single build job identified by builder_job_id and validates only that job's stored upload_path. However, the proxy forwards a user-controlled TUS resource suffix from the URL path to the builder service while injecting Capgo's privileged builder API key. Because the forwarded suffix is not bound to the authorized job's upload_path or upload_session_key, an attacker with a valid 'all' or 'write' Capgo API key and app.build_native permission for one application can misuse the proxy path for job A to write to the TUS upload resource of another job B if the resource suffix is known or exposed. This can lead to corruption of build artifacts. The vulnerability affects all versions of Capgo, and no patch was available at the time of the advisory.

Potential Impact

An attacker with valid Capgo API keys and appropriate permissions for one application can exploit this vulnerability to write to the upload resources of other build jobs, potentially corrupting build artifacts. This undermines the integrity of the build process and could disrupt software delivery or introduce malicious modifications. The vulnerability does not require user interaction or privileges beyond the specified API key permissions.

Mitigation Recommendations

No patch was available at the time of the advisory publication. Users should monitor the vendor's advisory for updates and apply official fixes once released. Until a fix is available, restrict API key permissions to the minimum necessary and avoid exposing resource suffixes that could be used to target other jobs. Review and limit access to Capgo API keys with 'all' or 'write' permissions and app.build_native scope to trusted entities only.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
VulnCheck
Date Reserved
2026-09-26T02:31:07.602Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6ab7c9a3f7a7c5410652fd0e

Added to database: 09/26/2026, 13:33:23 UTC

Last enriched: 09/26/2026, 14:18:08 UTC

Last updated: 09/26/2026, 14:47:51 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses