Impact
The vulnerability in Capgo before version 12.128.2, identified as CWE‑770, is a resource exhaustion flaw where the system fails to enforce storage and bandwidth quotas on the /files/upload/attachments endpoint. Attack readers are able to create publicly readable R2 objects that persist beyond normal bundle metadata and survive app deletion. This permits the consumption of platform resources without payment, potentially leading to abuse of storage and bandwidth and a denial‑of‑service scenario for the host.
Affected Systems
All Capgo installations running a version earlier than 12.128.2 are vulnerable. The flaw is triggered through the public /files/upload/attachments API endpoint that is accessible to applications possessing upload‑scoped API keys even when the app has been blocked by plan or quota limits. Administrators must verify their running version and the presence of upload‑scoped keys to assess exposure.
Risk and Exploitability
The CVSS base score is 5.3, indicating moderate severity. The EPSS score is < 1%, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires possession of an upload‑scoped API key and a plan surface compared to community‑wide flaws. However, after exploitation the attacker can repeatedly upload files, leading to uncontrolled growth in storage consumption and bandwidth usage, potentially causing denial‑of‑service conditions for the platform. Administrators should consider the likelihood of exposure based on the distribution of upload‑scoped keys.
OpenCVE Enrichment