PT-2026-56435 · Cap Go · Cap-Go
CVE-2026-56298
·
Published
2026-07-08
·
Updated
2026-07-08
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
The software fails to strip EXIF (Exchangeable Image File Format) metadata—a standard for storing metadata in image files—from images uploaded via the app information endpoint. This allows attackers to upload images and extract sensitive geolocation data and other embedded metadata from the files.
Recommendations
Update to version 12.128.2 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go