Vulnerability Description
Capgo before 12.128.2 contains an open redirect vulnerability in stripe_portal and stripe_checkout endpoints that accept unvalidated callbackUrl, successUrl, and cancelUrl parameters. Authenticated attackers can craft malicious billing URLs to redirect users to attacker-controlled domains for phishing and credential harvesting.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://github.com/Cap-go/capgo/security/advisories/GHSA-grc7-98pf-h8hq
- https://www.vulncheck.com/advisories/capgo-open-redirect-via-unvalidated-stripe-
- https://github.com/Cap-go/capgo/security/advisories/GHSA-grc7-98pf-h8hq
FAQ
What is CVE-2026-56330?
CVE-2026-56330 is a vulnerability with a CVSS score of 3.5 (LOW). Capgo before 12.128.2 contains an open redirect vulnerability in stripe_portal and stripe_checkout endpoints that accept unvalidated callbackUrl, successUrl, and cancelUrl parameters. Authenticated at...
How severe is CVE-2026-56330?
CVE-2026-56330 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-56330?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.