Impact
An authenticated user with the apikey_manager role is able to create API keys bound to higher‐rank deploy roles because the check that the caller carries the permissions of the role being assigned is missing. The exploit allows the attacker to craft keys that can push unrelated OTA JavaScript updates to all users of the organization’s apps.
Affected Systems
Capgo backend (capgo.app) versions 12.261.0 and earlier.
Risk and Exploitability
The vulnerability scores 7.1 on CVSS; EPSS data is not available and it is not in the KEV list. Attack requires authentication as an apikey_manager user and the use of the POST /apikey endpoint with a JWT session. Once exploited, the attacker can issue deploy‑role API keys and execute arbitrary updates, compromising confidentiality, integrity, and availability for end users. Due to the lack of a current public fix, the risk remains high until a patched release is deployed.
OpenCVE Enrichment