PT-2026-54036 · Cap Go · Cap-Go
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
Improper error handling occurs in the '/private/accept invitation' endpoint. When an invalid
magic invite string is provided, the system returns an HTTP 500 Internal Server Error instead of a standard 4xx client error. An attacker can use a public key to submit malformed magic invite string values, triggering server errors that may leak internal processing details.Recommendations
Update to version 12.128.2 or later.
As a temporary mitigation, restrict access to the '/private/accept invitation' endpoint or avoid using the
magic invite string parameter until the update is applied.Exploit
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go