PT-2026-54022 · Cap Go · Cap-Go
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
The application automatically authenticates users without confirmation when
access token and refresh token are provided in the URL query parameters of the '/login' endpoint. This behavior allows attackers to create malicious links that force victims into sessions controlled by the attacker, which also results in the exposure of tokens within browser history and server logs.Recommendations
Update to version 12.128.2 or later.
Avoid passing
access token and refresh token via URL query parameters in the '/login' endpoint.Exploit
Fix
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go