In all versions up to and including the current release (no patch available at time of publication), the transfer_app() database function transfers… (CVE-2026-100613)
capgo.app's transfer_app() database function does not remove or revalidate channel permission overrides when transferring apps between organizations. This allows former members of the source organization to retain permissions in the destination organization, enabling them to modify channels and serve attacker-selected app versions. No patch is available at the time of publication.
AI Analysis
Technical Summary
The vulnerability in capgo.app's transfer_app() function involves improper handling of channel_permission_overrides during app transfers between organizations. Specifically, the function transfers an app and its related records without deleting or revalidating existing channel permission overrides. Consequently, users who had channel permission overrides in the source organization retain those overrides after the transfer, despite lacking membership or RBAC bindings in the destination organization. These former members can use their authenticated JWT against the PostgREST API to modify the destination organization's channels, causing the /updates endpoint to serve malicious application versions. A previous fix (PR #3093) that validated organization membership when creating or updating overrides does not address stale overrides resulting from app transfers. No patch is available as of the publication date.
Potential Impact
An attacker who was formerly a member of the source organization can retain channel permission overrides in the destination organization after an app transfer. This unauthorized access allows them to modify channels to point to attacker-selected application versions, potentially distributing malicious updates to devices. The vulnerability impacts integrity but not confidentiality or availability.
Mitigation Recommendations
No official patch or fix is available at the time of publication. Users should monitor vendor advisories for updates. The previously proposed fix does not address stale overrides from app transfers, so additional manual review or temporary access controls may be necessary until a patch is released.
In all versions up to and including the current release (no patch available at time of publication), the transfer_app() database function transfers… (CVE-2026-100613)
Description
capgo.app's transfer_app() database function does not remove or revalidate channel permission overrides when transferring apps between organizations. This allows former members of the source organization to retain permissions in the destination organization, enabling them to modify channels and serve attacker-selected app versions. No patch is available at the time of publication.
CVSS v3.1
Score 5.3medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in capgo.app's transfer_app() function involves improper handling of channel_permission_overrides during app transfers between organizations. Specifically, the function transfers an app and its related records without deleting or revalidating existing channel permission overrides. Consequently, users who had channel permission overrides in the source organization retain those overrides after the transfer, despite lacking membership or RBAC bindings in the destination organization. These former members can use their authenticated JWT against the PostgREST API to modify the destination organization's channels, causing the /updates endpoint to serve malicious application versions. A previous fix (PR #3093) that validated organization membership when creating or updating overrides does not address stale overrides resulting from app transfers. No patch is available as of the publication date.
Potential Impact
An attacker who was formerly a member of the source organization can retain channel permission overrides in the destination organization after an app transfer. This unauthorized access allows them to modify channels to point to attacker-selected application versions, potentially distributing malicious updates to devices. The vulnerability impacts integrity but not confidentiality or availability.
Mitigation Recommendations
No official patch or fix is available at the time of publication. Users should monitor vendor advisories for updates. The previously proposed fix does not address stale overrides from app transfers, so additional manual review or temporary access controls may be necessary until a patch is released.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-jx6g-vmp7-mvxq
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-100613"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab89bebf7a7c54106942108
Added to database: 09/27/2026, 04:30:35 UTC
Last enriched: 09/27/2026, 04:45:31 UTC
Last updated: 09/27/2026, 05:47:33 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.