CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100620

LOWCVSS 3.8NVD feed

Published 26 September 2026 · tracked since 27 September 2026

Description

Capgo CLI (npm package @capgo/cli) through 7.98.2 is affected by an over-permissioned service account in its Android onboarding flow. When onboarding via Google OAuth, the CLI invites the generated Google Play service account with the account-wide Play Console permission CAN_MANAGE_DRAFT_APPS_GLOBAL

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-100620 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100620

LOWCVSS 3.8NVD feed

Published 26 September 2026 · tracked since 27 September 2026

Description

Capgo CLI (npm package @capgo/cli) through 7.98.2 is affected by an over-permissioned service account in its Android onboarding flow. When onboarding via Google OAuth, the CLI invites the generated Google Play service account with the account-wide Play Console permission CAN_MANAGE_DRAFT_APPS_GLOBAL

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]