PT-2026-99295 · Capgo.App · Capgo.App

·

CVE-2026-100624

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Capgo.app versions prior to 12.264.5
Description The '/build/upload/:jobId' TUS proxy endpoint fails to enforce upload expiry or build lifecycle state. While native build requests include an upload expires at timestamp and a 'pending' status, the upload proxy only verifies the app.build native permission before forwarding POST, PATCH, and HEAD requests to the internal builder. Consequently, an authenticated user with the app.build native permission can continue writing to a build upload session after the expiry time has passed or after the build has progressed beyond the upload phase, provided the internal builder service does not independently reject the request.
Recommendations Update to version 12.264.5.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100624
GHSA-MQR8-G67P-JM26

Affected Products

Capgo.App