---
id: CVE-2026-53867
title: Capgo < 12.128.2 - Orphaned File Retention via Profile Image Replacement
summary: >-
  Capgo before 12.128.2 fails to delete previously uploaded profile images from
  backend storage when users replace or remove them. Attackers can access
  orphaned image files through previously generated URLs, allowing unauthorized
  retrieval…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cvssSource: cna
cwe:
  - CWE-459
vendor: Capgo
product: Capgo
affected:
  - Capgo < 12.128.2
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-06-15T16:52:41.414750Z'
published: '2026-06-12'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T14:17:47.950Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-53867'
references:
  - url: 'https://github.com/Cap-go/capgo/security/advisories/GHSA-8p92-wcp2-c9j4'
    label: GHSA Advisory GHSA-8p92-wcp2-c9j4
  - url: >-
      https://www.vulncheck.com/advisories/capgo-orphaned-file-retention-via-profile-image-replacement
    label: >-
      VulnCheck Advisory: Capgo < 12.128.2 - Orphaned File Retention via Profile
      Image Replacement
tags:
  - cve.org
epss: 0.00183
epssPercentile: 0.08155
ingestedAt: '2026-09-24T15:45:56.728Z'
---

## Overview

Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remove them. Attackers can access orphaned image files through previously generated URLs, allowing unauthorized retrieval of user-uploaded content.

## Affected

- `Capgo < 12.128.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
