PT-2026-103954 · @Capacitor · Capacitor

CVE-2026-103922

·

Published

2026-10-01

·

Updated

2026-10-02

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Capacitor versions prior to 6.2.2 Capacitor versions prior to 7.6.9 Capacitor versions prior to 8.3.5 Capacitor versions prior to 8.4.3 Capacitor versions prior to 8.5.1
Description The Android and iOS WebView navigation guard validates the host and scheme of a target URL but fails to validate its path. This allows an attacker to direct a frame to the / capacitor http interceptor endpoint. The native proxy can then fetch a URL selected by the attacker and return the response as a document under the application's own origin. Consequently, scripts within that response can access same-origin storage, cookies, and registered Capacitor plugin capabilities. This issue persists even if CapacitorHttp is disabled, as the proxy path is served regardless of that configuration.
Recommendations Update to version 6.2.2 Update to version 7.6.9 Update to version 8.3.5 Update to version 8.4.3 Update to version 8.5.1

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103922

Affected Products

Capacitor