CVE-2026-100624
5.4 MEDIUMpublic exploit availablePublished 2026-09-26 · Updated 2026-09-28
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Capgo.app before 12.264.5 does not enforce upload expiry or build lifecycle state in the /build/upload/:jobId TUS proxy endpoint. When a native build request is created, an upload_expires_at timestamp (one hour) and a 'pending' status are stored in build_requests, but the upload proxy loads only app_id, owner_org, builder_job_id, and upload_path and checks only the app.build_native permission before forwarding POST, PATCH, and HEAD requests to the internal builder. As a result, an authenticated caller holding app.build_native permission for the app can continue writing to the build upload session after the stored expiry has passed or after the build has moved beyond the upload phase, unless the separate builder service independently rejects the request. The issue is fixed in 12.264.5.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Weaknesses
CWE-613
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-100502PoC
- MEDIUMCVE-2026-100554PoC
- HIGHCVE-2026-100711PoC
- UNSCOREDCVE-2026-101271
- MEDIUMCVE-2026-102367PoC
- MEDIUMCVE-2026-14465
- UNSCOREDCVE-2026-67242PoC
- HIGHCVE-2026-71206PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.