PT-2026-54022 · Cap Go · Cap-Go

·

CVE-2026-56224

·

Published

2026-06-30

·

Updated

2026-06-30

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.128.2
Description The application automatically authenticates users without confirmation when access token and refresh token are provided in the URL query parameters of the '/login' endpoint. This behavior allows attackers to create malicious links that force victims into sessions controlled by the attacker, which also results in the exposure of tokens within browser history and server logs.
Recommendations Update to version 12.128.2 or later. Avoid passing access token and refresh token via URL query parameters in the '/login' endpoint.

Exploit

Fix

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56224
GHSA-83F5-439G-PWMJ

Affected Products

Cap-Go