Capgo Build Upload Proxy Vulnerability CVE-2026-100625 Disclosed
Article Content
- •CVE-2026-100625 allows unauthorized artifact uploads across different build jobs.
- •All versions of Capgo are affected, with no patch available as of the advisory date.
- •The vulnerability has a CVSS score indicating a high severity risk.
Capgo (capgo.app) has a critical vulnerability (CVE-2026-100625) in its TUS upload proxy, allowing unauthorized access to build artifacts. The flaw arises from the proxy's inadequate validation of user-controlled resource suffixes, enabling attackers with valid API keys to manipulate uploads across different jobs. All versions of the affected system are vulnerable, and no patch was available at the time of the advisory publication. The CVSS scores for this vulnerability are 4.0 and 7.1, indicating a significant risk. The vulnerability was published on September 26, 2026, and is currently unpatched. Security professionals are urged to assess their exposure and monitor for potential exploitation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Capgo and CVE-2026-100625 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…