Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5ph3-fx7r-fpq3

Опубликовано: 01 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 5.4

Описание

Capgo console.capgo.app/login before 12.128.2 accepts access_token and refresh_token in URL query parameters, automatically authenticating users without confirmation. Attackers can craft malicious links to force victims into attacker-controlled sessions, exposing tokens in browser history and logs.

Capgo console.capgo.app/login before 12.128.2 accepts access_token and refresh_token in URL query parameters, automatically authenticating users without confirmation. Attackers can craft malicious links to force victims into attacker-controlled sessions, exposing tokens in browser history and logs.

EPSS

Процентиль: 19%
0.00271
Низкий

5.1 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-384

Связанные уязвимости

CVSS3: 5.4
nvd
2 месяца назад

Capgo console.capgo.app/login before 12.128.2 accepts access_token and refresh_token in URL query parameters, automatically authenticating users without confirmation. Attackers can craft malicious links to force victims into attacker-controlled sessions, exposing tokens in browser history and logs.

EPSS

Процентиль: 19%
0.00271
Низкий

5.1 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-384