CVE-2026-18311
CVE-2026-18311
CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th
Readwise Reader for Android contains a cross-site scripting vulnerability due to missing HTML sanitization in its processing of imported document metadata. Attacker-controlled fields such as the author meta tag are inserted into a WebView via innerHTML, enabling stored XSS that executes on synced devices when the malicious document is opened.
| Vendor | readwise |
| Product | reader |
| Published | Sep 25, 2026 |
| Last Updated | Sep 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for readwise reader
Be the first to know when new medium vulnerabilities affecting readwise reader are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Readwise / Reader
8.7.2 โค 8.10.1