PT-2026-49044 · Cap Go · Cap-Go

·

CVE-2026-53867

·

Published

2026-06-12

·

Updated

2026-06-13

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.128.2
Description The software fails to delete previously uploaded profile images from backend storage when users replace or remove them. This results in orphaned image files that can be accessed by attackers through previously generated URLs, leading to the unauthorized retrieval of user-uploaded content.
Recommendations Update to version 12.128.2.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53867
GHSA-8P92-WCP2-C9J4

Affected Products

Cap-Go