Capgo before 12.128.2 fails to delete previously uploaded...
Moderate severity
Unreviewed
Published
Jun 13, 2026
to the GitHub Advisory Database
•
Updated Jun 13, 2026
Description
Published by the National Vulnerability Database
Jun 12, 2026
Published to the GitHub Advisory Database
Jun 13, 2026
Last updated
Jun 13, 2026
Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remove them. Attackers can access orphaned image files through previously generated URLs, allowing unauthorized retrieval of user-uploaded content.
References