Authentication Bypass in Cap-go's OTP Verification Process
CVE-2026-56073
9.3CRITICAL
What is CVE-2026-56073?
Cap-go versions prior to 12.128.2 exhibit a vulnerability that allows attackers to bypass email verification through manipulation of OTP verification processes. This issue arises when attackers intercept OTP requests, subsequently modifying HTTP responses to incorrectly indicate that the verification has succeeded. As a result, unauthorized users may enable two-factor authentication (2FA) on accounts without proper verification, leading to potential account takeover and significant implications for user security.
Affected Version(s)
capgo 0 < 12.128.2
capgo 12.128.2
