Capgo npm Package Vulnerability: Critical SSO Bypass Risk
- Severity
- CRITICAL
- CVSS
- 9.1
- Affected component
- capgo (npm)
- Patched version
- Not yet available
An early warning has been issued for a critical vulnerability in the Capgo npm package. The package reportedly fails to restrict direct write access to the public.sso_providers table, which can allow an attacker to bypass SSO provisioning controls.
What happened
The Capgo npm package is under investigation for a critical vulnerability that allows unrestricted write access to the public.sso_providers table. This vulnerability can be exploited to bypass SSO provisioning controls, potentially allowing arbitrary domains to be asserted for SSO enforcement and disrupting normal login processes. The vulnerability affects all reported versions of the package.
This issue was first flagged on September 10, 2026, and is currently being investigated. The vulnerability has been assigned the identifier CVE-2026-88864 with a CVSS score of 9.1, indicating a critical severity level. There are no reports of this vulnerability being exploited in the wild at this time.
What to do about it
- Await a patch from the Capgo maintainers and monitor for any updates.
- Consider alternative SSO solutions until a fix is available.
- Review your application's SSO configuration and access controls to identify any potential exposure.
- No official fix has been published yet. Monitor the sources below for updates.
How 0Day would have caught this
capgo is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If your application uses the Capgo npm package, you are potentially affected by this vulnerability.
What should I do right now?
Await a patch from the Capgo maintainers and consider alternative SSO solutions until a fix is available.
Is there a patch available?
No official fix has been published yet. Monitor the sources for updates.
How severe is this vulnerability?
The vulnerability has been assigned a CVSS score of 9.1, indicating a critical severity level.