PT-2026-51147 · Cap Go · Cap-Go
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
Insufficient webhook URL validation allows for Server-Side Request Forgery (SSRF), a flaw where a server is tricked into making requests to an unintended location. Organization admins can configure webhooks pointing to loopback or internal addresses, such as
localhost or 127.0.0.1. When triggered, the backend performs outbound requests to these addresses and discloses the resulting error responses to users.Recommendations
Update to version 12.128.2.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go