PT-2026-54035 · Cap Go · Cap-Go
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
The software allows multiple public channels for the same application and platform to exist at the same time. When requests are made to the '/updates' endpoint without specifying a
defaultChannel, they implicitly resolve to a single hidden winner channel. This allows an authorized app or channel manager to create an ambiguous default update state and silently influence which bundle unnamed clients receive, which compromises release routing integrity and predictability.Recommendations
Update to version 12.128.2 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go