5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:L
Description
Capgo before 12.128.2 contains a server-side request forgery vulnerability in webhook URL validation that allows loopback and internal addresses. Organization admins can configure webhooks pointing to localhost or 127.0.0.1, and when triggered, the backend performs outbound requests to these addresses with error responses disclosed to users.
Basic Information
ID
CVE-2026-56227
Source
VulnCheck
Published
Jun 20, 2026 at 15:24
Affected Product
Vendor
Capgo
Product
Capgo
Affected Versions
Capgo Capgo 0