App ID Confusion Vulnerability in Capgo Product by Capgo
CVE-2026-56325
2.3LOW
What is CVE-2026-56325?
The vulnerability in Capgo arises from the use of ILIKE pattern matching for app_id lookups in the preview subdomain resolver. This allows underscore characters in app_id to function as SQL wildcards, potentially leading to unintended matches between app_ids that differ only by one character at positions where underscores appear. As a result, this can disrupt the preview functionality for legitimate applications and cause confusion between app_ids, posing security risks for users relying on precise app identification.
Affected Version(s)
Capgo 0 < 12.128.2
Capgo 12.128.2
