Cap Go · Cap-Go · CVE-2026-56221
**Name of the Vulnerable Software and Affected Versions**
Cap-go versions prior to 12.128.2
**Description**
Multiple SQL injection issues exist in cloudflare.ts where user-controlled values from API request bodies are interpolated directly into SQL query strings without sanitization or parameterization. Authenticated users with read-level API key permissions can inject arbitrary SQL through the `deviceIds`, `search`, `version name`, `cursor`, and `actions` parameters to access analytics data belonging to other users or applications.
**Recommendations**
Update to version 12.128.2 or later.