CVE-2026-56250Patch

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Capgo before 12.128.2 allows upload-scoped API keys to modify the mutable app_versions.r2_path field through PostgREST, enabling retargeting to arbitrary R2 bundle objects. Attackers can patch r2_path to point to victim objects, soft-delete the attacker-controlled version, and trigger the on_version_update cleanup function to delete the victim R2 object, causing denial of service and bundle availability disruption.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-08: 1Patch / Workaround · 2026-07-08: 1Technical Details · 2026-07-08: 107-08
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 HIGH - Capgo PostgREST r2_path retargeting leads to R2 object deletion (CVE-2026-56250) CVE-2026-56250 is a flaw in Capgo before 12.128.2 where upload-scoped API keys can modify the mutable app_versions.r2_path field via the PostgREST API, letting attackers repoint bundle references to arbitrary R2 objects. The root cause is improper authorization and input validation on a security-sensitive, mutable storage pointer field exposed through PostgREST. An attacker with an upload-scoped API key can PATCH r2_path to target a victim’s bundle object, then soft-delete their own version and rely on cleanup routines to delete the now-targeted victim R2 object. Impact is denial of service and disruption of bundle availability due to unintended deletion of legitimate R2 bundle objects. 👉 Affected: Capgo < 12.128.2 | Upgrade to 12.128.2

    Post summary

    CVE‑2026‑56250 is a denial‑of‑service flaw in Capgo that allows upload‑scoped API keys to delete R2 objects via PostgREST; upgrading to version 12.128.2 resolves the issue.

    00000172
    246 followersView on X

Explore more