Cap Go · Cap-Go · CVE-2026-56302
**Name of the Vulnerable Software and Affected Versions**
Capgo versions prior to 12.128.2
**Description**
An unsecured images bucket lacks row level security (RLS) controls, which are access control policies that restrict which users can see or modify specific rows in a database table. This misconfiguration allows unauthenticated remote attackers to read, insert, and delete stored app icons, potentially leading to the deletion of all icons and the leakage of sensitive `app IDs` and `user IDs`.
**Recommendations**
Update Capgo to version 12.128.2 or later.