{"id":"CVE-2026-100619","published":"2026-09-26T14:16:42.740","lastModified":"2026-09-28T20:57:50.143","description":"Capgo (capgo.app) blocks direct user inserts into the public.manifest table with a RESTRICTIVE row-level security policy, but that restriction can be bypassed indirectly. A principal holding an app-scoped upload/write/all API key (upload+ rights) or an authenticated user with write+ rights on an app can update public.app_versions.manifest on a version whose storage_provider is 'r2-direct', which is not covered by the bundle content-lock check. The on_version_update async worker trusts record.manifest and, using the service-role Supabase client, inserts the attacker-controlled file_name, file_hash, and s3_path into public.manifest before clearing app_versions.manifest. When a channel points to the crafted version, the /updates endpoint returns the service-role-created manifest entry as a client-facing download_url, enabling OTA manifest poisoning through a trusted async worker path. All versions are affected; no patch was available at the time of publication.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-266"],"vendors":[],"products":[],"references":[{"url":"https://github.com/Cap-go/capgo.app/security/advisories/GHSA-443r-w5p8-rhr2","tags":[]},{"url":"https://www.vulncheck.com/advisories/capgo-ota-manifest-poisoning-via-app-versions-manifest-bypass","tags":[]},{"url":"https://github.com/Cap-go/capgo.app/security/advisories/GHSA-443r-w5p8-rhr2","tags":[]}],"exploitRefs":[{"url":"https://github.com/Cap-go/capgo.app/security/advisories/GHSA-443r-w5p8-rhr2","tags":[]},{"url":"https://github.com/Cap-go/capgo.app/security/advisories/GHSA-443r-w5p8-rhr2","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows an attacker with certain API keys or write permissions to inject malicious files into the manifest, potentially leading to OTA manifest poisoning.","exploitability":"Exploitation requires an app-scoped upload/write/all API key or authenticated user with write+ rights. The attacker must also target a version with 'r2-direct' storage_provider.","blast_radius":"If exploited, this could lead to unauthorized access to files and potentially compromise the integrity of the application's manifest.","remediation":"Restrict access to the upload/write/all API key and ensure that only authorized users have write+ rights on the app.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","web","manifest-poisoning"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-30T09:02:44.001Z"}}