CVE-2026-56331
Received Received - Intake

BaseFortify

Vulnerability report for CVE-2026-56331, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-06-30

Last updated on: 2026-06-30

Assigner: VulnCheck

Description

Capgo before 12.128.2 contains improper error handling in the /private/accept_invitation endpoint that returns HTTP 500 instead of safe 4xx errors when magic_invite_string is invalid. Attackers can trigger this vulnerability using only the public key by submitting malformed magic_invite_string values to cause server errors and leak internal processing details.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-06-30
Last Modified
2026-06-30
Generated
2026-07-01
AI Q&A
2026-07-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
capgo capgo to 12.128.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-209 The product generates an error message that includes sensitive information about its environment, users, or associated data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in Capgo versions before 12.128.2 in the /private/accept_invitation endpoint. When an invalid magic_invite_string is submitted, the server improperly handles the error by returning an HTTP 500 status code instead of a safer 4xx error. This improper error handling can be exploited by attackers who only need the public key to submit malformed magic_invite_string values, causing server errors and potentially leaking internal processing details.

Impact Analysis

The impact of this vulnerability includes the possibility for attackers to cause server errors by submitting malformed inputs, which may lead to the exposure of internal processing details. This can aid attackers in gaining insights into the server's inner workings, potentially facilitating further attacks or exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56331. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart