Skip to content
Capgo Build Upload Proxy Vulnerability CVE-2026-100625 Disclosed

Capgo Build Upload Proxy Vulnerability CVE-2026-100625 Disclosed

First seen 27 Sep 2026, 17:21 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 27, 2026 at 19:09 UTC
  • •CVE-2026-100625 allows unauthorized artifact uploads across different build jobs.
  • •All versions of Capgo are affected, with no patch available as of the advisory date.
  • •The vulnerability has a CVSS score indicating a high severity risk.

Capgo (capgo.app) has a critical vulnerability (CVE-2026-100625) in its TUS upload proxy, allowing unauthorized access to build artifacts. The flaw arises from the proxy's inadequate validation of user-controlled resource suffixes, enabling attackers with valid API keys to manipulate uploads across different jobs. All versions of the affected system are vulnerable, and no patch was available at the time of the advisory publication. The CVSS scores for this vulnerability are 4.0 and 7.1, indicating a significant risk. The vulnerability was published on September 26, 2026, and is currently unpatched. Security professionals are urged to assess their exposure and monitor for potential exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-26
CVE-2026-100625 published
Capgo disclosed a vulnerability in its TUS upload proxy, impacting all versions and allowing unauthorized access to build artifacts.
cve.threatint.com
2026-09-26
Advisory published
No patch was available at the time of the advisory publication, leaving systems vulnerable.
Feedly
2026-09-26
CVE-2026-100706 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-27
Vulnerability details confirmed
Multiple sources confirmed the details of CVE-2026-100625, emphasizing the risk of unauthorized uploads.
cve.report

More articles in this cluster (5)

Following this threat?

Track Capgo and CVE-2026-100625 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed