PT-2026-99289 · Cap Go+1 · Cap-Go+1
CVSS v3.1
8.5
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Capgo (capgo.app) (affected versions not specified)
Description
An authorization flaw exists in the app icon update process. The 'PUT /app/:id' endpoint accepts a user-controlled
icon value and stores it in public.apps.icon url without verifying if the image path belongs to the target app's image namespace. Updating this value triggers the on app update trigger, which executes the cleanStoredImageMetadata() function using service-role credentials. This process downloads and re-uploads the referenced storage object with upsert: true. Consequently, an authenticated user with an app-limited write API key can force the privileged worker to overwrite private image objects, such as organization logos, that the user cannot normally access under Supabase Storage Row Level Security (RLS), a security feature that restricts data access based on user roles.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go
Supabase Storage