CVE-2026-56331
Capgo before 12.128.2 contains improper error handling in the /private/accept_invitation endpoint that returns HTTP 500 instead of safe 4xx
CVSS
5.3
Medio
EPSS
0.3%
p27
KEV
—
Exploit Today
8
0-100
Publicado: 30 jun 2026 · Última mod.: 1 jul 2026 · CWE-209
0.3%EPSS · 30 días0.3%
2026-08-182026-09-14
Capgo before 12.128.2 contains improper error handling in the /private/accept_invitation endpoint that returns HTTP 500 instead of safe 4xx errors when magic_invite_string is invalid. Attackers can trigger this vulnerability using only the public key by submitting malformed magic_invite_string values to cause server errors and leak internal processing details.
- github.comhttps://github.com/Cap-go/capgo/security/advisories/GHSA-34p8-fh3m-376x
- www.vulncheck.comhttps://www.vulncheck.com/advisories/capgo-improper-error-handling-in-accept-invitation-endpoint-via-invalid-magic-string
- github.comhttps://github.com/Cap-go/capgo/security/advisories/GHSA-34p8-fh3m-376x
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-55102——
——0hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, every API method in src/Vault.js passes failed requests through parseAxiosError(), which rethrows the raw AxiosError while retaining AxiosError.config and the equivalent response configuration. These objects can contain the X-Vault-Token request header and err.config.data request body, including submitted passwords or secret values. When a consuming application records the caught exception through console logging, structured loggers, monitoring, crash reporting, or an application performance monitoring service, the live Vault token and request secrets can be stored in plaintext and exposed to anyone with access to that output. A stolen token can permit unauthorized access to the Vault instance under the token's policies. This issue is fixed in version 0.5.2.2dCVE-2026-663066.5 MED42.3%
——13Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.8dCVE-2026-696845.5 MED39.3%
——12Generation of error message containing sensitive information in Windows Error Reporting allows an authorized attacker to disclose information locally.8dCVE-2026-695525.7 MED57.5%
——17Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized attacker to disclose information over a network.8dCVE-2026-692945.5 MED28.1%
——8Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally.8dCVE-2026-688865.5 MED39.3%
——12Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally.8d