PT-2026-51409 · Cap Go · Cap-Go
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.12
Description
The software fails to filter deleted app versions when joining channels during the resolution of the '/updates' endpoint. This occurs due to a missing
app versions.deleted filter in channel version joins, which allows deleted bundles to remain selectable and enables the deployment of these deleted bundles to devices.Recommendations
Update to version 12.128.12 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go