CyberRota Analysis
AI-GeneratedCapgo versions prior to 12.128.2 are vulnerable due to inadequate enforcement of plan and quota restrictions on the /files/upload/attachments endpoint, allowing unauthorized apps to create publicly accessible R2 objects. This flaw enables attackers to upload arbitrary files using upload-scoped API keys, leading to potential storage and bandwidth abuse, as these objects can persist even after app deletion. Organizations using Capgo should prioritize patching this vulnerability to mitigate the risk of unauthorized data exposure and resource exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Capgo before 12.128.2 fails to enforce plan/quota restrictions on the /files/upload/attachments endpoint, allowing plan-blocked apps to create publicly readable R2 objects. Attackers can upload arbitrary attachments using upload-scoped API keys that bypass plan checks, persist outside normal bundle metadata, and survive app deletion, enabling storage and bandwidth abuse.