Capgo image uploads retain EXIF metadata and expose location data

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2026-56298?

CVE-2026-56298 is a vulnerability classified as Exposure of Sensitive Information to an Unauthorized Actor, affecting Capgo (affected versions: < 12.128.2). This vulnerability is rated Medium, with a CVSS score of 5.3. Current sources do not report this vulnerability as exploited.

Overview

Original source data

Capgo before 12.128.2 fails to strip EXIF metadata from images uploaded via the app information endpoint, exposing sensitive geolocation data. Attackers can upload images containing EXIF metadata to extract geographic location information and other embedded metadata from uploaded files.

Affected products and scope

  • Capgo versions from 0 through less than 12.128.2 are identified as affected under semver.
  • 12.128.2 is listed by the advisory as patched and is identified by the record as unaffected.
  • The status of parallel release branches or later versions is not separately established by the available evidence.

Technical details

The flaw is in image handling at the app information endpoint. A network attacker with low privileges can upload an image containing EXIF metadata. Capgo does not remove that metadata before storing or returning the file, so geographic coordinates and other embedded fields may remain extractable from the uploaded image. This is an Exposure of Sensitive Information to an Unauthorized Actor weakness, classified as CWE-200. The available record does not identify the image-processing library, file-storage mechanism, or the complete set of EXIF fields that remain present.

Exploitability

The record describes network reachability with low privileges, low complexity, and no interaction from another user. The developer advisory provides a high-level reproduction flow: reach the app information endpoint, upload an image containing EXIF metadata, and inspect the metadata remaining in the uploaded file. The record marks public exploit as false and does not confirm exploitation in the wild. That status does not prove that no unreported tool or activity exists.

Technical impact

Successful exploitation can disclose EXIF data from images accepted through the app information endpoint, including location information when the image contains it. The primary effect is loss of confidentiality for the affected files; the record provides no evidence that the flaw permits data modification or service disruption. Access is described as network-based with low privileges and no interaction from another user. The practical impact depends on the metadata included in uploaded images and on who can access the resulting files.

Business impact

The flaw can expose geographic coordinates, capture times, and other metadata that users or organizations did not intend to publish with uploaded images. Depending on the actual EXIF content, this data may reveal sensitive locations, activities, or operational processes. Images uploaded before remediation should be reviewed if the system still retains original files with metadata. The record does not show that this flaw enables data modification or service disruption.

Remediation

  1. Upgrade Capgo to 12.128.2, which the advisory lists as the patched version for this issue.
  2. If an immediate upgrade is not possible, restrict the app information endpoint to the users and networks that require it, and avoid uploading or continuing to distribute images containing sensitive metadata. This is a precautionary measure, not a substitute for the confirmed patch.
  3. Review images uploaded before the upgrade and process or replace files that still contain sensitive EXIF metadata according to the organization’s retention policy.
  4. After upgrading, retest image upload with a sample file containing EXIF metadata to confirm that metadata is not retained in the stored or user-accessible file.

Detection

  1. Inventory Capgo deployments and identify the running versions; deployments on versions before the patched release should be treated as potentially exposed.
  2. Determine which deployments allow low-privilege accounts to reach the app information endpoint and upload images.
  3. Inspect representative uploaded images with an approved metadata-analysis tool to determine whether EXIF metadata, especially location data, remains present.
  4. Review application and file-storage logs for image uploads and subsequent access to files associated with this endpoint. This is precautionary monitoring, not a confirmed indicator of compromise.
  5. Absence of matching log evidence does not prove that a deployment is unaffected or that stored images contain no EXIF metadata.
Sources (8)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan