Cap Go · Cap-Go · CVE-2026-56332
**Name of the Vulnerable Software and Affected Versions**
Capgo versions prior to 12.128.2
**Description**
An open redirect issue exists in the 'confirm-signup' endpoint. The `confirmation url` parameter is not validated, which allows attackers to redirect users to arbitrary external websites. This can be used to facilitate phishing and credential harvesting attacks.
**Recommendations**
Update to version 12.128.2 or later.
As a temporary workaround, restrict access to the 'confirm-signup' endpoint or avoid using the `confirmation url` parameter until the update is applied.