Impact
Capgo prior to version 12.128.2 performs a wildcard comparison for the app_id during preview subdomain resolution, treating underscore characters as SQL wildcards. This flaw allows attackers to create application identifiers that differ from a legitimate app only by underscore placement, causing unintended matches. As a result, preview requests for one app can resolve to a different app or fail entirely, breaking preview functionality for users and potentially exposing sensitive data during preview sessions.
Affected Systems
The vulnerability affects the Capgo platform in all releases before 12.128.2. Users running any older Capgo instance are susceptible unless they have otherwise patched or custom‑modified the preview subdomain logic.
Risk and Exploitability
The CVSS score of 2.3 indicates a low severity flaw, and the EPSS score is not available, suggesting no known widespread exploitation. Attackers can exploit the issue remotely by creating an app with a crafted identifier that leverages wildcard matching to trigger unintended preview subdomain resolution. The flaw is not listed in the CISA KEV catalog, and no public exploits have been reported, but the functional impact on preview services warrants a patch as soon as possible.
OpenCVE Enrichment