CVE-2026-56218 Details
Description
Capgo before 12.128.2 fails to strip EXIF metadata including GPS geolocation data from uploaded images, allowing information disclosure. Attackers can download uploaded images and extract precise latitude and longitude coordinates revealing user physical location at capture time.
A vulnerability exists in Capgo versions prior to 12.128.2, where uploaded images retain EXIF metadata, including GPS geolocation data. This unstripped metadata can be accessed by downloading the images, allowing extraction of precise latitude and longitude coordinates that reveal the user's physical location at the time the image was taken. The issue arises because EXIF data is not sanitized before images are stored or served, creating a privacy risk by exposing sensitive location information without consent.
Users are advised to update to Capgo version 12.128.2 or later, where this vulnerability has been addressed. For those using earlier versions, it is recommended to manually strip EXIF metadata, especially GPS information, from images before uploading. Additionally, consider using server-side image processing tools to automatically remove sensitive metadata.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 20, 2026CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Cap-go/capgo/security/advisories/GHSA-c5w9-886p-9j2x | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/Cap-go/capgo/security/advisories/GHSA-c5w9-886p-9j2x | [email protected] | AdvisoryExploitRemedyVendor |
| https://www.vulncheck.com/advisories/capgo-exif-metadata-exposure-via-image-upload | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Capgo | < 12.128.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 20, 2026 | New CVE Received | [email protected] |
Volerion