Impact
Capgo versions prior to 12.128.2 contain an authorization bypass that allows write‑scoped API keys to mutate protected channel configuration fields. The bug arises from a null authentication check in the immutability trigger of PostgREST. Because the trigger does not verify that the API key has permission to change these fields, an attacker can alter sensitive attributes such as public, allow_emulator, and security‑related flags outside the normal application routes. This enables unauthorized modification of channel behavior and potentially opens additional attack surfaces.
Affected Systems
The vulnerability affects all installations of Capgo running a server component version earlier than 12.128.2. Any deployment of the affected server is at risk, as no specific platform variants are indicated.
Risk and Exploitability
The CVSS score of 7.1 places the flaw in the high severity range. Because it is tied to the possession of a write‑scoped API key, exploitation requires an attacker to already have such a key; however, once an attacker has one, no additional authentication is needed to change channel settings. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV, suggesting that there is currently no known active exploitation. Nonetheless, the scope of the impact – altering channel security flags – warrants immediate action.
OpenCVE Enrichment