Impact
The vulnerability in capgo.app versions up to 12.129.0 allows an attacker who does not need to authenticate to request a bundle via the public file read endpoint. Because the application does not verify whether a bundle has been marked deleted before it serves a cached copy, an attacker can download files that belong to bundles that have already been removed. In addition, every cached hit on a deleted bundle triggers the application to restore that bundle back into R2 storage, effectively recreating data that was intended to be permanently deleted. This results in unauthorized access to formerly deleted content and the potential for the application to consume additional storage resources or interfere with data-management workflows.
Affected Systems
The affected product is Cap‑go's capgo.app, with all releases through and including 12.129.0 vulnerable. No specific patch version is listed in the CVE description, but the issue is known to affect all pre‑12.129.1 instances of the software.
Risk and Exploitability
With a CVSS score of 8.7, this flaw provides significant impact and is considered high severity. The EPSS score is not available, so the current rate of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the public file read endpoint over the network, meaning the flaw can be exploited remotely by anyone with network access to the service. Consequently, administrators should treat this as a high-risk issue that can lead to data exposure and storage misuse if left unpatched.
OpenCVE Enrichment