PT-2026-103954 · @Capacitor · Capacitor
CVE-2026-103922
·
Published
2026-10-01
·
Updated
2026-10-02
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Capacitor versions prior to 6.2.2
Capacitor versions prior to 7.6.9
Capacitor versions prior to 8.3.5
Capacitor versions prior to 8.4.3
Capacitor versions prior to 8.5.1
Description
The Android and iOS WebView navigation guard validates the host and scheme of a target URL but fails to validate its path. This allows an attacker to direct a frame to the
/ capacitor http interceptor endpoint. The native proxy can then fetch a URL selected by the attacker and return the response as a document under the application's own origin. Consequently, scripts within that response can access same-origin storage, cookies, and registered Capacitor plugin capabilities. This issue persists even if CapacitorHttp is disabled, as the proxy path is served regardless of that configuration.Recommendations
Update to version 6.2.2
Update to version 7.6.9
Update to version 8.3.5
Update to version 8.4.3
Update to version 8.5.1
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Capacitor