OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100625

HIGH · CVSS 7.1 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Capgo's upload proxy is vulnerable due to improper validation of user-controlled resource suffixes, allowing authenticated users with specific API permissions to manipulate and corrupt build artifacts across different jobs. This can lead to unauthorized access and modification of sensitive build data, posing a significant risk to application integrity. Organizations using Capgo should prioritize addressing this vulnerability, especially those with active build processes that rely on the affected upload functionality.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100625
Severity
HIGH
CVSS
7.1
EPSS
0.25%

Original NVD Description

Capgo (capgo.app) exposes a native build TUS upload proxy (supabase/functions/_backend/public/build/upload.ts) that authorizes a caller against a single build job identified by the supplied builder_job_id and validates only that job's stored upload_path, but then forwards the user-controlled TUS resource suffix taken from /build/upload/:jobId/* to the builder service while injecting Capgo's privileged builder API key. Because the forwarded suffix is never bound to the authorized job's upload_path or upload_session_key, a caller holding a valid 'all' or 'write' Capgo API key with app.build_native permission for one application can use its authorized proxy path for job A to write to the TUS upload resource of another job B, provided that resource suffix is known or exposed, corrupting that build's artifacts. All versions are affected; no patch was available at the time of advisory publication.