Vulnerability Description
Capgo before 12.128.2 fails to enforce plan/quota restrictions on the /files/upload/attachments endpoint, allowing plan-blocked apps to create publicly readable R2 objects. Attackers can upload arbitrary attachments using upload-scoped API keys that bypass plan checks, persist outside normal bundle metadata, and survive app deletion, enabling storage and bandwidth abuse.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/Cap-go/capgo/security/advisories/GHSA-q52j-ggvx-cr4v
- https://www.vulncheck.com/advisories/capgo-plan-bypass-via-unrestricted-attachme
- https://github.com/Cap-go/capgo/security/advisories/GHSA-q52j-ggvx-cr4v
FAQ
What is CVE-2026-56309?
CVE-2026-56309 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Capgo before 12.128.2 fails to enforce plan/quota restrictions on the /files/upload/attachments endpoint, allowing plan-blocked apps to create publicly readable R2 objects. Attackers can upload arbitr...
How severe is CVE-2026-56309?
CVE-2026-56309 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-56309?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.