Capgo
- < 12.128.2
A vulnerability in Capgo versions prior to 12.128.2 allows upload-scoped API keys to manipulate the app_versions.r2_path field through PostgREST. This manipulation enables the retargeting of R2 bundle objects. Attackers can change the r2_path to point to victim objects, soft-delete the version they control, and activate a cleanup function that deletes the victim's R2 object, leading to a denial-of-service and disruption of bundle availability.
Exploitation of this vulnerability results in the arbitrary deletion of R2 bundle objects, causing a denial-of-service for affected downloads and disrupting over-the-air update availability.
The vulnerability can be reproduced by using an upload-scoped API key to access the PostgREST API. First, create a version with a harmless R2 object and upload it using the normal upload-link flow. Then, create another version and patch its r2_path to point to the victim object's path. After soft-deleting this version, the cleanup trigger will delete the victim R2 object, confirming the exploitation.
Users are advised to update to Capgo version 12.128.2 or later, where this vulnerability has been patched.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.