Unrated severityNVD Advisory· Published Jul 8, 2026· Updated Jul 8, 2026
Capgo - HTML Injection Leading to Open Redirection in Organization Settings
CVE-2026-56283
Description
Capgo before 12.128.2 contains an html injection vulnerability in the organization settings endpoint that allows attackers to inject malicious HTML content. Attackers can craft payloads in the organization name field to redirect users to untrusted websites, enabling phishing attacks and reputational damage.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/Cap-go/capgo/security/advisories/GHSA-vhvc-gxfh-m85gmitrevendor-advisory
- www.vulncheck.com/advisories/capgo-html-injection-leading-to-open-redirection-in-organization-settingsmitrethird-party-advisory
News mentions
0No linked articles in our index yet.