Threat intelligence dashboard
CVE-2026-100622high

capgo.app through 12.129.0 Cache Restoration of Deleted Bundles

capgo.app through 12.129.0 fails to verify deletion status when serving cached bundle artifacts from the public file read endpoint. Unauthenticated attackers can download deleted bundles using cached URLs and trigger restoration of deleted objects into R2 storage on cache hits.

Risk score

8.7

CVSS 4.0

Vendor
Cap-go
Product
capgo.app
CWE
CWE-200
Published
Sep 26, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

capgo.app

Cap-go

Version / rangeStatusType
0 to 12.129.0affectedsemver

Technical metrics

8.7

CVSS 4.0

Severity
high
Source
VulnCheck
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

7.5

CVSS 3.1

Severity
high
Source
VulnCheck
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N