maven package report

Is com.capacitorjs:core safe?

1 known vulnerability, worst severity CRITICAL.

// reach

0 direct dependencies

none carry a known advisory

    0 packages depend on it

    an advisory here reaches each of them

      Create a free accountfor every dependency path, dependent and what to upgrade
      // ai model usage

      Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


      cvss
      0.0
      critical

      severity out of 10

      epss
      0.00%
      low

      chance of exploitation in 30 days, 11th percentile of all CVEs

      xyz score
      not scored

      CyberXYZ composite out of 10

      fig. 01 — GHSA-rvm3-566m-v7fv, the advisory selected below

      // 1 advisories

      GHSA-rvm3-566m-v7fv

      CRITICALCVE-2026-103922
      // impact

      Capacitor's WebView navigation guard validated only the host and scheme of a target URL, not its path. Because the internal HTTP proxy path (/capacitorhttpinterceptor) is served at the application's own origin, a frame navigation to it was always treated as in-app navigation and allowed.

      Loading that path as a document caused the native layer to fetch an arbitrary, caller-specified URL and return the response body to the WebView at the app's own origin. Script in that response then ran with full same-origin trust: access to localStorage, cookies, and every native capability the application exposes through its registered Capacitor plugins.

      The proxy handler was additionally served regardless of whether the CapacitorHttp plugin was enabled, so applications that never enabled CapacitorHttp were also affected.

      Exploitation requires a victim to activate a link inside the application's WebView. Any Capacitor application that renders user-controlled or unsanitized links (chat messages, comments, rich-text content) is a viable delivery surface.

      Both Android and iOS are affected.

      // patches

      Two changes on each platform:

      • The navigation guard now blocks frame navigations whose path is the internal

      proxy path.

      • The proxy handler is served only when CapacitorHttp is enabled, and never

      for a document (main frame) request.

      Legitimate CapacitorHttp usage is unaffected. fetch and XMLHttpRequest are subresource requests and do not pass through the navigation guard.

      Upgrade to a patched version, then rebuild and redistribute your application.

      // workarounds

      If you cannot upgrade immediately, note first that disabling CapacitorHttp is not sufficient on affected versions, because the proxy path is served regardless of that setting.

      Registered plugins are consulted before the navigation guard runs, so a small plugin can block the path. On Android, override shouldOverrideLoad(Uri url) and return true when url.getPath() starts with /capacitorhttpinterceptor. On iOS, implement shouldOverrideLoad(:) and return true for the same path. Returning true cancels the navigation; return null/nil for all other URLs so normal navigation is unchanged.

      Independently, sanitize user-controlled link targets before rendering them in the WebView.

      // cvss v3.1 vector

      CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

      Attack vector
      Network
      Attack complexity
      Low
      Privileges required
      None
      User interaction
      Required
      Scope
      Changed
      Confidentiality
      High
      Integrity
      High
      Availability
      None

      Checked 2026-10-06 at 02:03 UTC. The most recent advisory here was published 2026-10-05. Updated continuously from NVD, GHSA, OSV and CNA feeds.

      Think a verdict here is wrong? Tell us — we respond within 2 business days.