🔐 CVE Alert

CVE-2026-78325

UNKNOWN 0.0

XSS in Standard Notes on Android via Malicious Google Keep and Evernote HTML Import

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a victim imports a crafted .enex or Google Keep HTML file, leading to theft of encryption keys and note data, and arbitrary invocation of native device APIs.

CWE CWE-79
Vendor standard notes
Product standard notes
Published Sep 7, 2026
Last Updated Sep 8, 2026
Stay Ahead of the Next One

Get instant alerts for standard notes standard notes

Be the first to know when new unknown vulnerabilities affecting standard notes standard notes are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Standard Notes / Standard Notes
0 ≤ v3.201.24

References

NVD ↗ CVE.org ↗ EPSS Data ↗
proton.me: https://proton.me/security/security-advisories github.com: https://github.com/standardnotes/app/compare/%40standardnotes/desktop%403.201.24...%40standardnotes/desktop%403.201.25

Credits

Luca Regne, https://regne.me/