Junglewise Threat Intelligence

CVE-2026-56298: Capgo sensitive metadata exposure in app information image upload

CVE-2026-56298 · Severity: medium · CVSS 4.3 · Published 2026-07-08

Technologies: Capgo. Vendors: Capgo.

Executive brief

Capgo, a platform for managing app updates and information, fails to remove sensitive metadata from images uploaded to its console. This allows users to view hidden information in uploaded files, such as the exact GPS coordinates where a photo was taken. This could lead to the unintended disclosure of private location data or other sensitive device information.

Technical details

A sensitive information disclosure vulnerability exists in Capgo versions prior to 12.128.2 due to improper sanitization of uploaded image files. The application fails to strip Exchangeable Image File Format (EXIF) metadata from images uploaded through the app information endpoint (e.g., at console.capgo.app). An authenticated attacker can upload images containing embedded metadata and subsequently retrieve that data, including GPS coordinates and device details. This is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The issue is resolved in version 12.128.2.

Affected products

  • Capgo Capgo < 12.128.2

Timeline

  • 2026-02-26: advisory: Initial GitHub security advisory published
  • 2026-07-08: disclosed: CVE published and NVD record created

References

Related threats