PT-2026-51219 · Unknown · @Capgo/Cli
CVSS v4.0
6.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Capgo CLI versions prior to 12.128.2
Description
Arbitrary file overwrite and credential exposure issues exist in login and build credentials operations. The software follows symbolic links (symlinks)—which are files that point to another file or directory—without proper validation. This allows attackers to create malicious symlinks within repositories to overwrite arbitrary files or expose credentials by assigning world-readable permissions when a developer executes the CLI.
Recommendations
Update to version 12.128.2 or later.
Exploit
Fix
Link Following
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
@Capgo/Cli