CVE-2026-100619
8.8 HIGHpublic exploit availablePublished 2026-09-26 · Updated 2026-09-28
AI risk analysis
- Summary
- The flaw allows an attacker with certain API keys or write permissions to inject malicious files into the manifest, potentially leading to OTA manifest poisoning.
- Exploitability
- Exploitation requires an app-scoped upload/write/all API key or authenticated user with write+ rights. The attacker must also target a version with 'r2-direct' storage_provider.
- Blast radius
- If exploited, this could lead to unauthorized access to files and potentially compromise the integrity of the application's manifest.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Restrict access to the upload/write/all API key and ensure that only authorized users have write+ rights on the app.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Capgo (capgo.app) blocks direct user inserts into the public.manifest table with a RESTRICTIVE row-level security policy, but that restriction can be bypassed indirectly. A principal holding an app-scoped upload/write/all API key (upload+ rights) or an authenticated user with write+ rights on an app can update public.app_versions.manifest on a version whose storage_provider is 'r2-direct', which is not covered by the bundle content-lock check. The on_version_update async worker trusts record.manifest and, using the service-role Supabase client, inserts the attacker-controlled file_name, file_hash, and s3_path into public.manifest before clearing app_versions.manifest. When a channel points to the crafted version, the /updates endpoint returns the service-role-created manifest entry as a client-facing download_url, enabling OTA manifest poisoning through a trusted async worker path. All versions are affected; no patch was available at the time of publication.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-266
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-86583
- CRITICALCVE-2025-15399
- HIGHCVE-2025-51457
- CRITICALCVE-2025-66455PoC
- MEDIUMCVE-2025-71420PoC
- CRITICALCVE-2026-100291
- CRITICALCVE-2026-10050PoC
- HIGHCVE-2026-100520PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.