PT-2026-57173 · Cap Go · Cap-Go
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
An issue exists due to non-bijective decoding of double underscores to dots during preview hostname parsing. This allows attackers to register app IDs containing underscores that collide with the dotted app IDs of other tenants, leading to preview misrouting and denial of preview access for victim applications.
Recommendations
Update to version 12.128.2 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go