---
id: CVE-2026-56236
title: >-
  Capgo CLI before 12.128.2 contains arbitrary file overwrite vulnerabilities in
  login and build credentials operations that follow symlinks without validation
summary: >-
  Capgo CLI before 12.128.2 contains arbitrary file overwrite vulnerabilities in
  login and build credentials operations that follow symlinks without
  validation. Attackers can create malicious symlinks in repositories to
  overwrite arbitrary…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N'
cwe:
  - CWE-59
vendor: capgo
product: cli
affected:
  - cli < 12.128.2
published: '2026-06-21'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:21.637'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-56236'
references:
  - url: 'https://github.com/Cap-go/capgo/security/advisories/GHSA-8mpm-q7mh-8fvh'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/capgo-cli-arbitrary-file-overwrite-via-symlink-following-in-local-credential-operations
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-06-22T18:10:58.100784Z'
epss: 0.00183
epssPercentile: 0.07243
ingestedAt: '2026-10-08T16:52:14.692Z'
---

## Overview

Capgo CLI before 12.128.2 contains arbitrary file overwrite vulnerabilities in login and build credentials operations that follow symlinks without validation. Attackers can create malicious symlinks in repositories to overwrite arbitrary files or expose credentials with world-readable permissions when developers run the CLI.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
