PT-2026-99293 · Capgo.App · Capgo.App

CVE-2026-100622

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions capgo.app versions prior to 12.129.0
Description The application fails to verify the deletion status when serving cached bundle artifacts from the public file read endpoint. This allows unauthenticated attackers to download bundles that have been deleted by using cached URLs. Additionally, cache hits can trigger the restoration of deleted objects into R2 storage, which is a cloud-based object storage service.
Recommendations Update capgo.app to version 12.129.0 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100622
GHSA-26X3-6MR7-989P

Affected Products

Capgo.App