CVE-2026-56218

Capgo before 12.128.2 fails to strip EXIF metadata including GPS geolocation data from uploaded images, allowing information disclosure. Attackers can download uploaded images and extract precise latitude and longitude coordinates revealing user physical location at capture time.
Configurations

No configuration.

History

23 Jun 2026, 04:17

Type Values Removed Values Added
References () https://github.com/Cap-go/capgo/security/advisories/GHSA-c5w9-886p-9j2x - () https://github.com/Cap-go/capgo/security/advisories/GHSA-c5w9-886p-9j2x -

20 Jun 2026, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-20 16:17

Updated : 2026-06-23 04:17


NVD link : CVE-2026-56218

Mitre link : CVE-2026-56218

CVE.ORG link : CVE-2026-56218


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor