Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. @capacitor/android
  4. ›
  5. CVE-2026-103922

CVE-2026-103922: Capacitor Android and iOS: remote content can be loaded at the app origin via the internal HTTP proxy path

October 5, 2026

Capacitor’s WebView navigation guard validated only the host and scheme of a target URL, not its path. Because the internal HTTP proxy path (/_capacitor_http_interceptor_) is served at the application’s own origin, a frame navigation to it was always treated as in-app navigation and allowed.

Loading that path as a document caused the native layer to fetch an arbitrary, caller-specified URL and return the response body to the WebView at the app’s own origin. Script in that response then ran with full same-origin trust: access to localStorage, cookies, and every native capability the application exposes through its registered Capacitor plugins.

The proxy handler was additionally served regardless of whether the CapacitorHttp plugin was enabled, so applications that never enabled CapacitorHttp were also affected.

Exploitation requires a victim to activate a link inside the application’s WebView. Any Capacitor application that renders user-controlled or unsanitized links (chat messages, comments, rich-text content) is a viable delivery surface.

Both Android and iOS are affected.

References

  • github.com/advisories/GHSA-rvm3-566m-v7fv
  • github.com/ionic-team/capacitor/commit/430356a91e1419fc66862dc09835081aa501677e
  • github.com/ionic-team/capacitor/commit/745b5f805bf77bc6463977cc7d718cd9de44ccbc
  • github.com/ionic-team/capacitor/commit/80b6c5e81d062e1e158914040f49e044d95b7ccb
  • github.com/ionic-team/capacitor/commit/85ccc44151fdd5ae5e0d806d875766ef4b84ad5d
  • github.com/ionic-team/capacitor/commit/af9a287fef45f0ac68ce640cb42fed2d06b0f1b4
  • github.com/ionic-team/capacitor/commit/d5e3170ba0ff155fc542b7e6d16cff5201406540
  • github.com/ionic-team/capacitor/commit/ee586ae680887ba99d066616f976db149542d922
  • github.com/ionic-team/capacitor/releases/tag/8.5.1
  • github.com/ionic-team/capacitor/security/advisories/GHSA-rvm3-566m-v7fv
  • nvd.nist.gov/vuln/detail/CVE-2026-103922

Code Behaviors & Features

Detect and mitigate CVE-2026-103922 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 6.0.0 before 6.2.2, all versions starting from 7.0.0 before 7.6.9, all versions starting from 8.0.0 up to 8.3.4, all versions starting from 8.3.5 before 8.4.3, all versions starting from 8.5.0 before 8.5.1

Fixed versions

  • 6.2.2
  • 7.6.9
  • 8.4.3
  • 8.5.1

Solution

Upgrade to versions 6.2.2, 7.6.9, 8.4.3, 8.5.1 or above.

Impact 9.3 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-346: Origin Validation Error
  • CWE-441: Unintended Proxy or Intermediary ('Confused Deputy')

Source file

npm/@capacitor/android/CVE-2026-103922.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 06 Oct 2026 00:15:57 +0000.