CVE-2026-103922
Received Received - Intake

Path Traversal in Capacitor WebView Navigation

Vulnerability report for CVE-2026-103922, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: GitHub, Inc.

Description

Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1, the Android and iOS WebView navigation guard validates a target URL's host and scheme but not its path, allowing a victim who activates an untrusted link to navigate a frame to /_capacitor_http_interceptor_. The native proxy can fetch an attacker-selected URL and return the response as a document at the application's own origin, allowing script in that response to access same-origin storage, cookies, and registered Capacitor plugin capabilities. Applications remain affected when CapacitorHttp is disabled because affected releases serve the proxy path regardless of that setting. This issue is fixed in versions 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
ionic capacitor 6.0.0
ionic capacitor 6.2.2
ionic capacitor 7.6.9
ionic capacitor 8.3.5
ionic capacitor 8.4.3
ionic capacitor 8.5.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-346 The product does not properly verify that the source of data or communication is valid.
CWE-441 The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Capacitor allows an attacker to load malicious content at the app's origin via the internal HTTP proxy path. The WebView navigation guard only checked host and scheme, not path, enabling frame navigation to /_capacitor_http_interceptor_. The native proxy fetches attacker-selected URLs and returns responses at the app's origin, allowing scripts to access same-origin storage, cookies, and Capacitor plugin capabilities.

Detection Guidance

Detecting this vulnerability requires checking if your Capacitor application is running a vulnerable version and if the internal HTTP proxy path is accessible. Inspect the Capacitor version in your app's dependencies and verify if the proxy path /_capacitor_http_interceptor_ can be navigated to in iframes or frames. Use browser developer tools to check network requests and frame navigation behavior.

Impact Analysis

An attacker could trick a user into clicking a malicious link, causing the app to load attacker-controlled content at its own origin. This allows the attacker to steal sensitive data like cookies or localStorage, execute arbitrary scripts, and access native device features exposed by Capacitor plugins. Exploitation requires user interaction with a link within the app's WebView.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive user data, violating GDPR's data protection principles and HIPAA's requirements for safeguarding protected health information. The ability to execute scripts with full bridge access may result in data breaches, non-compliance with privacy regulations, and potential legal consequences.

Mitigation Strategies

Upgrade Capacitor to a patched version (6.2.2, 7.6.9, 8.3.5, 8.4.3, or 8.5.1 or later). Rebuild and redistribute your application. If immediate upgrade is not possible, implement temporary workarounds such as blocking the proxy path via plugin overrides on Android and iOS or sanitizing user-controlled links to prevent navigation to the proxy path.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103922. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart