CVE-2026-56236

Capgo CLI before 12.128.2 contains arbitrary file overwrite vulnerabilities in login and build credentials operations that follow symlinks without validation. Attackers can create malicious symlinks in repositories to overwrite arbitrary files or expose credentials with world-readable permissions when developers run the CLI.
Configurations

No configuration.

History

21 Jun 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-21 14:16

Updated : 2026-06-22 19:17


NVD link : CVE-2026-56236

Mitre link : CVE-2026-56236

CVE.ORG link : CVE-2026-56236


JSON object : View

Products Affected

No product.

CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')