CVE-2026-18320
CVE-2026-18320
CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th
Readwise Reader for Android uses a sanitize-html configuration that permits all attributes on SVG and PATH elements due to a wildcard attribute rule. This configuration fails to remove script-capable attributes such as event handlers (e.g., 'onload', 'onerror'). An attacker could supply a document containing malicious SVG content that survives sanitization and executes script wher rendered in the Reader WebView, resulting in client-side cross-site scripting (XSS).
| Vendor | readwise |
| Product | reader |
| Published | Sep 25, 2026 |
| Last Updated | Sep 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for readwise reader
Be the first to know when new medium vulnerabilities affecting readwise reader are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Readwise / Reader
8.7.2 < 8.10.1