Impact
Capgo versions before 12.244.1 are vulnerable due to a cross‑tenant integrity flaw in the metadata‑cleaning worker. The worker trusts image object keys that originate from mutable database rows without verifying ownership, which allows an authenticated user to insert a victim tenant’s image key into a row they control. When the worker processes the row, it downloads the victim’s image and re‑uploads it with sanitized metadata, effectively rewriting the image object. This flaw represents a classic confused‑deputy weakness that undermines isolation guarantees and enables attackers to silently alter image metadata.
Affected Systems
The vulnerability affects Capgo deployments running any version prior to 12.244.1, specifically the Capgo app managed under the Cap-go:capgo.app product line. No specific patch version is listed beside the target version; upgrading to 12.244.1 or later removes the flaw.
Risk and Exploitability
The CVSS v3 score of 8.7 classifies this issue as high severity. The EPSS score is not available, indicating that current exploitation data is unknown. The flaw requires an authenticated attacker with the ability to update mutable database rows, a condition that can be met in environments where tenant credentials grant such access. Once exploited, the attacker can covertly modify metadata of cross‑tenant image objects, bypassing storage access controls and violating tenant isolation. The vulnerability is not currently listed in the CISA KEV catalog, but its high impact and proven exploitation pathway warrant immediate attention.
OpenCVE Enrichment