Ghostwire

CVE-2026-56227: Capgo before 12.128.2 contains a server-side request forgery vulnerability in webhook URL validation that allows...

MEDIUM CVSS 0.0

Published: June 20, 2026 | Last Modified: June 20, 2026

Description

Capgo before 12.128.2 contains a server-side request forgery vulnerability in webhook URL validation that allows loopback and internal addresses. Organization admins can configure webhooks pointing to localhost or 127.0.0.1, and when triggered, the backend performs outbound requests to these addresses with error responses disclosed to users.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References