
🚨 HIGH - Capgo PostgREST r2_path retargeting leads to R2 object deletion (CVE-2026-56250) CVE-2026-56250 is a flaw in Capgo before 12.128.2 where upload-scoped API keys can modify the mutable app_versions.r2_path field via the PostgREST API, letting attackers repoint bundle references to arbitrary R2 objects. The root cause is improper authorization and input validation on a security-sensitive, mutable storage pointer field exposed through PostgREST. An attacker with an upload-scoped API key can PATCH r2_path to target a victim’s bundle object, then soft-delete their own version and rely on cleanup routines to delete the now-targeted victim R2 object. Impact is denial of service and disruption of bundle availability due to unintended deletion of legitimate R2 bundle objects. 👉 Affected: Capgo < 12.128.2 | Upgrade to 12.128.2
Post summary
CVE‑2026‑56250 is a denial‑of‑service flaw in Capgo that allows upload‑scoped API keys to delete R2 objects via PostgREST; upgrading to version 12.128.2 resolves the issue.
