Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-383x-vh5q-x2q9

Опубликовано: 20 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 5.4

Описание

Capgo before 12.128.2 contains a server-side request forgery vulnerability in webhook URL validation that allows loopback and internal addresses. Organization admins can configure webhooks pointing to localhost or 127.0.0.1, and when triggered, the backend performs outbound requests to these addresses with error responses disclosed to users.

Capgo before 12.128.2 contains a server-side request forgery vulnerability in webhook URL validation that allows loopback and internal addresses. Organization admins can configure webhooks pointing to localhost or 127.0.0.1, and when triggered, the backend performs outbound requests to these addresses with error responses disclosed to users.

EPSS

Процентиль: 18%
0.0026
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 5.4
nvd
около 2 месяцев назад

Capgo before 12.128.2 contains a server-side request forgery vulnerability in webhook URL validation that allows loopback and internal addresses. Organization admins can configure webhooks pointing to localhost or 127.0.0.1, and when triggered, the backend performs outbound requests to these addresses with error responses disclosed to users.

EPSS

Процентиль: 18%
0.0026
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-918