NPM · SEPTEMBER 2026 · EARLY WARNING

Capgo npm Package Vulnerability: Critical SSO Bypass Risk

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.1
Affected component
capgo (npm)
Patched version
Not yet available
CVE-2026-88864

An early warning has been issued for a critical vulnerability in the Capgo npm package. The package reportedly fails to restrict direct write access to the public.sso_providers table, which can allow an attacker to bypass SSO provisioning controls.

What happened

The Capgo npm package is under investigation for a critical vulnerability that allows unrestricted write access to the public.sso_providers table. This vulnerability can be exploited to bypass SSO provisioning controls, potentially allowing arbitrary domains to be asserted for SSO enforcement and disrupting normal login processes. The vulnerability affects all reported versions of the package.

This issue was first flagged on September 10, 2026, and is currently being investigated. The vulnerability has been assigned the identifier CVE-2026-88864 with a CVSS score of 9.1, indicating a critical severity level. There are no reports of this vulnerability being exploited in the wild at this time.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If capgo is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If your application uses the Capgo npm package, you are potentially affected by this vulnerability.

What should I do right now?

Await a patch from the Capgo maintainers and consider alternative SSO solutions until a fix is available.

Is there a patch available?

No official fix has been published yet. Monitor the sources for updates.

How severe is this vulnerability?

The vulnerability has been assigned a CVSS score of 9.1, indicating a critical severity level.

Sources

Join the 0Day waitlist →

← Back to all threats