PT-2026-57167 · Npm · @Capgo/Capacitor-Updater
CVE-2026-56254
·
Published
2026-07-10
·
Updated
2026-07-10
CVSS v4.0
8.3
High
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
@capgo/capacitor-updater versions prior to 12.128.2
Description
The end-to-end encryption scheme distributes the private key to every device that downloads the application. Since the public key can be derived from the private key, an attacker who compromises the Capgo server or performs a man-in-the-middle attack can create a validly signed update bundle, leading devices to install updates not created by the original app maker.
Recommendations
Update to version 12.128.2 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Capgo/Capacitor-Updater