PT-2026-51147 · Cap Go · Cap-Go

·

CVE-2026-56227

·

Published

2026-06-20

·

Updated

2026-06-22

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.128.2
Description Insufficient webhook URL validation allows for Server-Side Request Forgery (SSRF), a flaw where a server is tricked into making requests to an unintended location. Organization admins can configure webhooks pointing to loopback or internal addresses, such as localhost or 127.0.0.1. When triggered, the backend performs outbound requests to these addresses and discloses the resulting error responses to users.
Recommendations Update to version 12.128.2.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56227
GHSA-48HC-53HV-6X3F

Affected Products

Cap-Go