Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-56224

Опубликовано: 30 июн. 2026
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

Capgo console.capgo.app/login before 12.128.2 accepts access_token and refresh_token in URL query parameters, automatically authenticating users without confirmation. Attackers can craft malicious links to force victims into attacker-controlled sessions, exposing tokens in browser history and logs.

EPSS

Процентиль: 19%
0.00271
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-384

Связанные уязвимости

CVSS3: 5.4
github
2 месяца назад

Capgo console.capgo.app/login before 12.128.2 accepts access_token and refresh_token in URL query parameters, automatically authenticating users without confirmation. Attackers can craft malicious links to force victims into attacker-controlled sessions, exposing tokens in browser history and logs.

EPSS

Процентиль: 19%
0.00271
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-384