Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-56254

Опубликовано: 10 июл. 2026
Источник: nvd
CVSS3: 7
EPSS Низкий

Описание

In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app. Because the public key can be derived from the private key, an attacker performing a man-in-the-middle attack or compromising the Capgo server can create a validly signed update bundle and cause devices to install an update not produced by the original app maker.

EPSS

Процентиль: 9%
0.00195
Низкий

7 High

CVSS3

Дефекты

CWE-320

Связанные уязвимости

CVSS3: 7
github
2 месяца назад

In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app. Because the public key can be derived from the private key, an attacker performing a man-in-the-middle attack or compromising the Capgo server can create a validly signed update bundle and cause devices to install an update not produced by the original app maker.

EPSS

Процентиль: 9%
0.00195
Низкий

7 High

CVSS3

Дефекты

CWE-320