Capgo EXIF Metadata Exposure Vulnerability in App Information Image Upload

Vulnerability

A vulnerability exists in Capgo versions prior to 12.128.2, where the application fails to remove EXIF metadata from images uploaded through the app information endpoint. This oversight allows attackers to access sensitive geolocation data and other embedded metadata from the uploaded files.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive geolocation information and other EXIF metadata from uploaded images.

Reproduction

To reproduce this vulnerability, upload an image containing EXIF metadata, including geolocation information, via the app information endpoint. After the image is uploaded, the EXIF metadata can be extracted and viewed, revealing the sensitive geolocation data that was not stripped from the image before upload.

Remediation

Users can update to Capgo version 12.128.2 or later, where this vulnerability has been addressed.

Added: Jul 8, 2026, 2:35 PM
Updated: Jul 8, 2026, 2:35 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.6
remediation
0.0
relevance
9.7
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.