CyberRota Analysis
AI-GeneratedA policy bypass vulnerability in Capgo versions prior to 12.128.2 allows attackers with app-scoped API keys to downgrade encrypted bundles to an unencrypted state by manipulating the app_versions table through PostgREST. This exploitation can compromise OTA security controls, making it critical for organizations using Capgo to prioritize patching to maintain the integrity of their application security. Users managing sensitive data or relying on encrypted bundles should address this vulnerability promptly to mitigate potential risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Capgo before 12.128.2 contains a policy bypass vulnerability in app_versions update enforcement that allows app-scoped API keys to downgrade encrypted bundles to non-encrypted state. Attackers with app-scoped all API keys can directly update the app_versions table via PostgREST to clear session_key and key_id fields, bypassing organization-enforced encrypted-bundle policies and weakening OTA security controls.