Vulnerability Description
In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app. Because the public key can be derived from the private key, an attacker performing a man-in-the-middle attack or compromising the Capgo server can create a validly signed update bundle and cause devices to install an update not produced by the original app maker.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/Cap-go/capgo/security/advisories/GHSA-j2f4-4pfc-p8rx
- https://www.vulncheck.com/advisories/capacitor-updater-end-to-end-encryption-byp
FAQ
What is CVE-2026-56254?
CVE-2026-56254 is a vulnerability with a CVSS score of 7.0 (HIGH). In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app. Because the public key can be derived fr...
How severe is CVE-2026-56254?
CVE-2026-56254 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-56254?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.