VYPR
Medium severity4.3NVD Advisory· Published Jun 12, 2026· Updated Jun 15, 2026

CVE-2026-53867

CVE-2026-53867

Description

Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remove them. Attackers can access orphaned image files through previously generated URLs, allowing unauthorized retrieval of user-uploaded content.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Cap Go/Capgoinferred2 versions
    <12.128.2+ 1 more
    • (no CPE)range: <12.128.2
    • (no CPE)range: <12.128.2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.