Unrated severityNVD Advisory· Published Jun 20, 2026
Capgo - EXIF Metadata Exposure via Image Upload
CVE-2026-56218
Description
Capgo before 12.128.2 fails to strip EXIF metadata including GPS geolocation data from uploaded images, allowing information disclosure. Attackers can download uploaded images and extract precise latitude and longitude coordinates revealing user physical location at capture time.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/Cap-go/capgo/security/advisories/GHSA-c5w9-886p-9j2xmitrevendor-advisory
- www.vulncheck.com/advisories/capgo-exif-metadata-exposure-via-image-uploadmitrethird-party-advisory
News mentions
1- Capgo: 21 CVEs Disclosed Together — Unauthenticated Cross-Tenant Bugs and Scope Escalation Lead the BatchVypr Intelligence · Jun 20, 2026