VulDB 🛡@vuldbActive Exploitation
The CTI team reports observing numerous attacks against Capgo CVE-2026-56330, but offers no PoC, exploit code, patch, or technical detail.
Vulmon Vulnerability Feed@VulmonFeedsGeneral
The post announces an open redirect flaw in Capgo’s Stripe endpoints (pre‑12.128.2) and links to vulnerability details and a notification, but provides no proof of concept, exploit, patch, or evidence of active exploitation.
Infoflowcloud@infoflowcloudDisclosure
CVE-2026-56330 is a newly disclosed open redirect flaw in Capgo (≤12.128.2) that impacts stripe_portal and stripe_checkout endpoints by allowing unvalidated callbackUrl, successUrl, and cancel parameters.
CVE@CVEnewDisclosure
Capgo versions before 12.128.2 suffer an open‑redirect flaw through unvalidated callback URLs in stripe_portal and stripe_checkout endpoints.