PT-2026-54036 · Cap Go · Cap-Go

·

CVE-2026-56331

·

Published

2026-06-30

·

Updated

2026-06-30

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.128.2
Description Improper error handling occurs in the '/private/accept invitation' endpoint. When an invalid magic invite string is provided, the system returns an HTTP 500 Internal Server Error instead of a standard 4xx client error. An attacker can use a public key to submit malformed magic invite string values, triggering server errors that may leak internal processing details.
Recommendations Update to version 12.128.2 or later. As a temporary mitigation, restrict access to the '/private/accept invitation' endpoint or avoid using the magic invite string parameter until the update is applied.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56331
GHSA-34P8-FH3M-376X

Affected Products

Cap-Go