Denial of Service Vulnerability in Capgo by Capgo
CVE-2026-56255
5.3MEDIUM
What is CVE-2026-56255?
Capgo prior to version 12.128.2 is susceptible to a denial of service issue in the POST /app/demo endpoint. Authenticated users possessing organization write permissions can exploit this vulnerability to generate an unlimited number of demo applications. This absence of rate limiting and quota enforcement allows attackers to invoke this endpoint repetitively, leading to approximately 138 database write operations for every request. Such activities can severely degrade performance, increase operational costs, and lead to overall service instability.
Affected Version(s)
Capgo 0 < 12.128.2
Capgo 12.128.2
