Junglewise Threat Intelligence

CVE-2026-56224: Capgo session fixation via URL query parameters in login page

CVE-2026-56224 · Severity: medium · CVSS 5.4 · Published 2026-06-30

Technologies: Capgo. Vendors: Capgo.

Executive brief

Capgo, a platform for managing app updates, contained a security flaw in its login page. The system allowed users to be automatically logged in using security tokens provided directly in a web link. An attacker could send a malicious link to a victim to force them into an attacker-controlled account session, potentially leading to the exposure of sensitive session data in browser history or server logs.

Technical details

A session fixation and login CSRF vulnerability exists in the Capgo web application (console.capgo.app) prior to version 12.128.2. The 'checkLogin' function in the login page component parses 'access_token' and 'refresh_token' directly from URL query parameters and passes them to 'supabase.auth.setSession' without user confirmation or state validation. This allows a remote attacker to craft a URL that, when clicked by a victim, forces the victim's browser to authenticate into a session controlled by the attacker. Furthermore, passing sensitive tokens in query strings increases the risk of credential exposure via browser history, proxy logs, and referrer headers. The issue is resolved in version 12.128.2 by removing support for tokens in query parameters.

Affected products

  • Capgo Capgo < 12.128.2

Timeline

  • 2026-03-03: advisory: GitHub Security Advisory published
  • 2026-06-30: disclosed: CVE published to NVD

References

Related threats