PT-2026-57172 · Cap Go · Cap-Go
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
Improper validation in the 'accept invitation' endpoint allows the creation of user accounts before captcha validation is enforced. This enables attackers to bypass captcha protection by sending POST requests with invalid captcha tokens, resulting in the creation of unwanted accounts and the consumption of invite links.
Recommendations
Update to version 12.128.2 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go