Capgo CLI before 12.128.2 contains arbitrary file overwrite vulnerabilities in login and build credentials operations that follow symlinks without validation. Attackers can create malicious symlinks in repositories to overwrite arbitrary files or expose credentials with world-readable permissions when developers run the CLI.
Metrics
Affected Vendors & Products
References
History
Sun, 21 Jun 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Capgo CLI before 12.128.2 contains arbitrary file overwrite vulnerabilities in login and build credentials operations that follow symlinks without validation. Attackers can create malicious symlinks in repositories to overwrite arbitrary files or expose credentials with world-readable permissions when developers run the CLI. | |
| Title | Capgo CLI - Arbitrary File Overwrite via Symlink-Following in Local Credential Operations | |
| Weaknesses | CWE-59 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-21T13:26:51.450Z
Reserved: 2026-06-19T21:50:06.625Z
Link: CVE-2026-56236
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-21T16:45:03Z