No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 23 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Capgo
Capgo cli |
|
| Vendors & Products |
Capgo
Capgo cli |
Mon, 22 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 21 Jun 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Capgo CLI before 12.128.2 contains arbitrary file overwrite vulnerabilities in login and build credentials operations that follow symlinks without validation. Attackers can create malicious symlinks in repositories to overwrite arbitrary files or expose credentials with world-readable permissions when developers run the CLI. | |
| Title | Capgo CLI - Arbitrary File Overwrite via Symlink-Following in Local Credential Operations | |
| Weaknesses | CWE-59 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-22T18:12:12.186Z
Reserved: 2026-06-19T21:50:06.625Z
Link: CVE-2026-56236
Updated: 2026-06-22T18:11:06.426Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-23T21:03:50Z