PT-2026-99293 · Capgo.App · Capgo.App
CVE-2026-100622
·
Published
2026-09-26
·
Updated
2026-09-28
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
capgo.app versions prior to 12.129.0
Description
The application fails to verify the deletion status when serving cached bundle artifacts from the public file read endpoint. This allows unauthenticated attackers to download bundles that have been deleted by using cached URLs. Additionally, cache hits can trigger the restoration of deleted objects into R2 storage, which is a cloud-based object storage service.
Recommendations
Update capgo.app to version 12.129.0 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Capgo.App