---
id: CVE-2026-56298
title: Capgo - EXIF Metadata Exposure in App Information Image Upload
summary: >-
  Capgo before 12.128.2 fails to strip EXIF metadata from images uploaded via
  the app information endpoint, exposing sensitive geolocation data. Attackers
  can upload images containing EXIF metadata to extract geographic location
  informatio…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cvssSource: cna
cwe:
  - CWE-200
vendor: Capgo
product: Capgo
affected:
  - Capgo < 12.128.2
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-07-08T14:30:45.448910Z'
published: '2026-07-08'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T15:27:22.391Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-56298'
references:
  - url: 'https://github.com/Cap-go/capgo/security/advisories/GHSA-62jm-xp28-x4xw'
    label: GitHub Security Advisory (GHSA-62jm-xp28-x4xw)
  - url: >-
      https://www.vulncheck.com/advisories/capgo-exif-metadata-exposure-in-app-information-image-upload
    label: >-
      VulnCheck Advisory: Capgo - EXIF Metadata Exposure in App Information
      Image Upload
tags:
  - cve.org
epss: 0.00306
epssPercentile: 0.21286
ingestedAt: '2026-10-05T16:25:58.415Z'
---

## Overview

Capgo before 12.128.2 fails to strip EXIF metadata from images uploaded via the app information endpoint, exposing sensitive geolocation data. Attackers can upload images containing EXIF metadata to extract geographic location information and other embedded metadata from uploaded files.

## Affected

- `Capgo < 12.128.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
