PT-2026-51219 · Unknown · @Capgo/Cli

·

CVE-2026-56236

·

Published

2026-03-18

·

Updated

2026-06-21

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Capgo CLI versions prior to 12.128.2
Description Arbitrary file overwrite and credential exposure issues exist in login and build credentials operations. The software follows symbolic links (symlinks)—which are files that point to another file or directory—without proper validation. This allows attackers to create malicious symlinks within repositories to overwrite arbitrary files or expose credentials by assigning world-readable permissions when a developer executes the CLI.
Recommendations Update to version 12.128.2 or later.

Exploit

Fix

Link Following

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56236
GHSA-8MPM-Q7MH-8FVH

Affected Products

@Capgo/Cli