PT-2026-99289 · Cap Go+1 · Cap-Go+1

·

CVE-2026-100618

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Capgo (capgo.app) (affected versions not specified)
Description An authorization flaw exists in the app icon update process. The 'PUT /app/:id' endpoint accepts a user-controlled icon value and stores it in public.apps.icon url without verifying if the image path belongs to the target app's image namespace. Updating this value triggers the on app update trigger, which executes the cleanStoredImageMetadata() function using service-role credentials. This process downloads and re-uploads the referenced storage object with upsert: true. Consequently, an authenticated user with an app-limited write API key can force the privileged worker to overwrite private image objects, such as organization logos, that the user cannot normally access under Supabase Storage Row Level Security (RLS), a security feature that restricts data access based on user roles.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100618

Affected Products

Cap-Go
Supabase Storage