Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 26 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | capgo.app through 12.129.0 fails to verify deletion status when serving cached bundle artifacts from the public file read endpoint. Unauthenticated attackers can download deleted bundles using cached URLs and trigger restoration of deleted objects into R2 storage on cache hits. | |
| Title | capgo.app through 12.129.0 Cache Restoration of Deleted Bundles | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-26T13:29:45.609Z
Reserved: 2026-09-26T02:31:07.602Z
Link: CVE-2026-100622
No data.
Status : Received
Published: 2026-09-26T14:16:43.157
Modified: 2026-09-26T14:16:43.157
Link: CVE-2026-100622
No data.
OpenCVE Enrichment
No data.