CVE-2026-53867 PUBLISHED

Capgo < 12.128.2 - Orphaned File Retention via Profile Image Replacement

Assigner: VulnCheck
Reserved: 10.06.2026 Published: 12.06.2026 Updated: 12.06.2026

Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remove them. Attackers can access orphaned image files through previously generated URLs, allowing unauthorized retrieval of user-uploaded content.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor Cap-go
Product capgo
Versions Default: unaffected
  • affected from 0 to 12.128.2 (excl.)
  • Version 12.128.2 is unaffected

Credits

  • Naitik Gupta reporter

References

Problem Types

  • Incomplete Cleanup CWE