{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3acapgocapgo.app/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:capgo:capgo.app:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.5,"id":"CVE-2026-100618"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["capgo.app (all versions)"],"_cs_severities":["high"],"_cs_tags":["web-application","privilege-escalation","cloud"],"_cs_type":"advisory","_cs_vendors":["Capgo"],"content_html":"\u003cp\u003eCapgo (capgo.app) is vulnerable to an authorization flaw within the app icon update mechanism. The PUT /app/:id endpoint fails to validate that the provided 'icon' value resides within the specific app's image namespace. By submitting a path pointing to an out-of-scope storage object, an authenticated user with limited write access can influence the application's backend worker.\u003c/p\u003e\n\u003cp\u003eWhen the 'icon' field is updated, it triggers the 'on_app_update' event. A background worker, executing with elevated service-role credentials (supabaseAdmin()), subsequently processes this record by calling 'cleanStoredImageMetadata()'. This function performs a download and re-upload (upsert) operation on the attacker-supplied object path. Because the worker operates with administrative privileges, it bypasses Supabase Row Level Security (RLS) constraints, effectively allowing an attacker to overwrite sensitive files, such as organization logos, to which they would otherwise lack read or write permissions. This vulnerability affects all current versions of the service.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eAn attacker exploiting this vulnerability can perform unauthorized file overwrites within the Supabase storage backend. This can lead to the defacement of organization-level assets or potential operational disruption by replacing legitimate system images with malicious or arbitrary content, bypassing standard access controls.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor API access logs for PUT requests to the '/app/:id' endpoint involving suspicious or unexpected file paths in the 'icon' parameter.\u003c/li\u003e\n\u003cli\u003eReview Supabase storage bucket permissions and audit the 'on_app_update' trigger function for any unauthorized modifications.\u003c/li\u003e\n\u003cli\u003eImplement additional input validation on the application layer to enforce strict namespace checks for user-provided image paths before they reach the backend processing trigger.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized upsert operations within sensitive storage directories where organization logos or administrative assets are stored.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-26T16:59:54Z","date_published":"2026-09-26T16:59:54Z","id":"https://feed.craftedsignal.io/briefs/2026-09-capgo-auth-flaw/","summary":"An authorization vulnerability in the Capgo PUT /app/:id endpoint allows authenticated users to trick a privileged backend worker into overwriting restricted storage objects.","title":"Authorization Flaw in Capgo App Icon Update Path","url":"https://feed.craftedsignal.io/briefs/2026-09-capgo-auth-flaw/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:capgo:capgo.app:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}