{"id":"CVE-2026-100614","published":"2026-09-26T14:16:42.050","lastModified":"2026-09-28T20:57:50.143","description":"Capgo before 12.244.1 contains a cross-tenant integrity vulnerability in the metadata-cleaning worker that trusts image object keys from mutable database rows without validating ownership. An authenticated attacker can place a victim tenant's image key in a row they control, causing the service-role worker to download and re-upload that object with sanitized metadata. Attackers can silently modify metadata in cross-tenant image objects by supplying known victim keys during authorized row updates, bypassing storage access controls through the confused-deputy metadata worker.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-639"],"vendors":[],"products":[],"references":[{"url":"https://github.com/Cap-go/capgo.app/security/advisories/GHSA-rcrw-pg2v-j9xg","tags":[]},{"url":"https://www.vulncheck.com/advisories/capgo-before-12.244.1-cross-tenant-image-overwrite-via-metadata-worker","tags":[]},{"url":"https://github.com/Cap-go/capgo.app/security/advisories/GHSA-rcrw-pg2v-j9xg","tags":[]}],"exploitRefs":[{"url":"https://github.com/Cap-go/capgo.app/security/advisories/GHSA-rcrw-pg2v-j9xg","tags":[]},{"url":"https://github.com/Cap-go/capgo.app/security/advisories/GHSA-rcrw-pg2v-j9xg","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows an authenticated attacker to modify metadata in cross-tenant image objects by supplying known victim keys, bypassing storage access controls.","exploitability":"Exploitation requires an authenticated attacker with control over a mutable database row and knowledge of the victim's key. This is moderately hard to exploit.","blast_radius":"If exploited, the vulnerability could lead to silent modification of metadata in cross-tenant image objects, potentially compromising data integrity.","remediation":"Upgrade to Capgo 12.244.1 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","metadata","cross-tenant"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:02:04.488Z"}}