Junglewise Threat Intelligence

CVE-2026-56283: Capgo HTML injection in organization settings

CVE-2026-56283 · Severity: medium · CVSS 5.4 · Published 2026-07-08

Technologies: Capgo. Vendors: Capgo.

Executive brief

Capgo, a platform for managing app updates and organization settings, contains a security flaw in its organization settings dashboard. An attacker with a basic account can inject malicious code into the organization name field, which is then displayed to other users. This can be used to trick employees or partners into visiting fraudulent websites, potentially leading to credential theft or phishing attacks.

Technical details

An HTML injection vulnerability exists in Capgo versions prior to 12.128.2 within the organization settings endpoint. The root cause is improper neutralization of user-supplied input in the 'organization name' field (CWE-79). An authenticated attacker can inject malicious HTML tags that are rendered in the browsers of other users, such as team members invited to the organization. This can be leveraged to perform open redirection or phishing attacks. Exploitation requires low administrative privileges to modify organization settings and interaction from a victim user who views the affected page. The issue is resolved in version 12.128.2.

Affected products

  • Capgo Capgo < 12.128.2

Timeline

  • 2026-02-10: advisory: Initial GitHub security advisory published
  • 2026-07-08: disclosed: NVD publication and CVE assignment

References

Related threats