Impact
Capgo versions prior to 12.128.12 contain a billing authorization bypass in the plan_valid calculation. When an organization’s system’s internal plan_valid expression does not correctly enforce the authoritative billing gate. This mismatch allows attackers to continue accessing non‑payment protected endpoints such as /updates, /stats, /channel_self, and attachment uploads after credit depletion, potentially leading to unauthorized use of the service and additional billing costs. The vulnerability is classified as a CWE‑285 type of authorization flaw and carries a CVSS score of 5.3, indicating moderate severity. No exploitation evidence or proof of concept was provided in the advisory, but the description implies an attack can be performed by making requests to the affected endpoints once the account credit is exhausted.
Affected Systems
All Capgo installations running any version before 12.128.12 are affected. The issue is present in the Capgo product suite, and any deployment of the open‑source code prior to the 12.128.12 release is vulnerable. Systems that have not applied the official patch remain exposed to the described billing bypass.
Risk and Exploitability
The CVSS score of 5.3 suggests moderate risk, and the EPSS score ofless than 1%) indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is inferred as an authorized user with API or web access, or any entity able to target the service endpoints. Since the flaw is based on a logical divergence between two internal checks, exploitation requires only that the attacker be able to access the protected prerequisites beyond normal service usage are described, so the vulnerability is potentially addressable by any organization using Capgo before the specified version upgrade.
OpenCVE Enrichment