Cap Go · Cap-Go · CVE-2026-56283
**Name of the Vulnerable Software and Affected Versions**
Capgo versions prior to 12.128.2
**Description**
An HTML injection issue exists in the organization settings endpoint. Attackers can inject malicious HTML content by crafting payloads in the `organization name` field, which can be used to redirect users to untrusted websites, facilitating phishing attacks and causing reputational damage.
**Recommendations**
Update to version 12.128.2 or later.