Description
In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app. Because the public key can be derived from the private key, an attacker performing a man-in-the-middle attack or compromising the Capgo server can create a validly signed update bundle and cause devices to install an update not produced by the original app maker.
Published: 2026-07-10
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from the updater’s design, in which a private key is distributed can be derived from the private key, an attacker who performs a man‑in‑the‑middle attack on the update channel or compromises the Capgo server can forge a signed update bundle that the device will accept as legitimate. Installing such a malicious update would allow the attacker to execute arbitrary code on the device, compromising confidentiality, integrity, and availability of the application and its underlying system.

Affected Systems

Capgo capacitor-updater (Cap-go/capgo) versions prior to 12.128.2 are affected by the key distribution flaw in the updater module.

Risk and Exploitability

The CVSS score of 8.3 signals a high severity risk, while the EPSS score of <1% indicates a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a man‑in‑the‑middle interception of the update channel or the Capgo server, both of which enable the attacker to create and serve a validly signed malicious update bundle.

Generated by OpenCVE AI on July 26, 2026 at 13:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the capacitor-updater package to version 12.128.2 or later, which removes the private key distribution flaw.
  • If an immediate upgrade is not viable, restrict network access so that only trusted Capgo servers can be contacted, preventing a compromised server from delivering forged updates.
  • Validate update bundle signatures independently on client devices to detect tampered bundles.

Generated by OpenCVE AI on July 26, 2026 at 13:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Capacitor-updater
Capacitor-updater capacitor-updater
Vendors & Products Capacitor-updater
Capacitor-updater capacitor-updater

Fri, 10 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Description In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app. Because the public key can be derived from the private key, an attacker performing a man-in-the-middle attack or compromising the Capgo server can create a validly signed update bundle and cause devices to install an update not produced by the original app maker.
Title capacitor-updater - End-to-End Encryption Bypass via Private Key Distribution
Weaknesses CWE-320
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Capacitor-updater Capacitor-updater
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-10T15:17:16.881Z

Reserved: 2026-06-19T21:56:09.655Z

Link: CVE-2026-56254

cve-icon Vulnrichment

Updated: 2026-07-10T15:17:12.803Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T14:00:17Z

Weaknesses