Known Vulnerabilities for Capgo by Cap-go
Listed below are 10 of the newest known vulnerabilities associated with "Capgo" by "Cap-go".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-56339 json | Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST SECURITY DEFI... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-56338 json | Capgo before 12.128.2 contains a denial of service vulnerability in the /auth/v1/otp endpoint that prevents email verificatio... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-56337 json | Capgo before 12.128.2 contains an information disclosure vulnerability in the public.exist_app_v2 RPC function that allows un... | Not Provided | 2026-06-24 | 2026-06-24 |
| CVE-2026-56336 json | Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /private/sso/check-domain endpo... | Not Provided | 2026-07-12 | 2026-07-14 |
| CVE-2026-56335 json | Capgo before 12.128.2 contains an authorization bypass vulnerability where write-scoped API keys can directly mutate protecte... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-56334 json | Capgo before 12.128.2 lacks an UPDATE row-level security policy for the build_requests table, preventing API-key and anonymou... | Not Provided | 2026-06-30 | 2026-07-01 |
| CVE-2026-56333 json | Capgo before 12.128.2 contains a server-side validation bypass vulnerability in organization security settings that allows au... | Not Provided | 2026-06-30 | 2026-07-01 |
| CVE-2026-56332 json | Capgo before 12.128.2 contains an open redirect vulnerability in the confirm-signup endpoint that allows attackers to redirec... | Not Provided | 2026-06-20 | 2026-06-22 |
| CVE-2026-56331 json | Capgo before 12.128.2 contains improper error handling in the /private/accept_invitation endpoint that returns HTTP 500 inste... | Not Provided | 2026-06-30 | 2026-07-01 |
| CVE-2026-56330 json | Capgo before 12.128.2 contains an open redirect vulnerability in stripe_portal and stripe_checkout endpoints that accept unva... | Not Provided | 2026-06-20 | 2026-06-23 |