Impact
Capgo CLI up to version 7.98.2 incorrectly grants Google Play service accounts full developer permissions during Android onboarding. The CLI invites the service account with the global CAN_MANAGE_DRAFT_APPS_GLOBAL permission, even though the user interface states the account is limited to a single app with release-only rights. This mismatch enables anyone in possession of the service account key to create, edit, and delete draft applications for the entire Google Play developer account, compromising application integrity and potentially facilitating malicious releases.
Affected Systems
Affected deployment is Capgo CLI, a JavaScript package named @capgo/cli, for all releases up to and including 7.98.2. No subsequent versions are listed as fixed.
Risk and Exploitability
The attack likely requires possession of the service account key, which could be obtained through compromised Google OAuth flows or insider access, and does not rely on network vulnerabilities in the CLI itself. The CVSS score of 5.1 indicates moderate severity, the EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. However, the ability to manipulate all draft applications within a developer account makes this flaw potentially high impact to a developer’s application pipeline.
OpenCVE Enrichment