{"id":"CVE-2026-56298","title":"Capgo - EXIF Metadata Exposure in App Information Image Upload","summary":"Capgo before 12.128.2 fails to strip EXIF metadata from images uploaded via the app information endpoint, exposing sensitive geolocation data. Attackers can upload images containing EXIF metadata to extract geographic location informatio…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cvssSource":"cna","cwe":["CWE-200"],"vendor":"Capgo","product":"Capgo","affected":["Capgo < 12.128.2"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-07-08T14:30:45.448910Z"},"published":"2026-07-08","updated":"2026-10-05","sourceUpdated":"2026-10-05T15:27:22.391Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-56298","references":[{"url":"https://github.com/Cap-go/capgo/security/advisories/GHSA-62jm-xp28-x4xw","label":"GitHub Security Advisory (GHSA-62jm-xp28-x4xw)"},{"url":"https://www.vulncheck.com/advisories/capgo-exif-metadata-exposure-in-app-information-image-upload","label":"VulnCheck Advisory: Capgo - EXIF Metadata Exposure in App Information Image Upload"}],"tags":["cve.org"],"epss":0.00306,"epssPercentile":0.21286,"ingestedAt":"2026-10-05T16:25:58.415Z","slug":"CVE-2026-56298","body":"## Overview\n\nCapgo before 12.128.2 fails to strip EXIF metadata from images uploaded via the app information endpoint, exposing sensitive geolocation data. Attackers can upload images containing EXIF metadata to extract geographic location information and other embedded metadata from uploaded files.\n\n## Affected\n\n- `Capgo < 12.128.2`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}