{"id":"CVE-2026-18311","title":"Readwise Reader for Android contains a cross-site scripting vulnerability due to missing HTML sanitization in its processing of imported document metadata","summary":"Readwise Reader for Android contains a cross-site scripting vulnerability due to missing HTML sanitization in its processing of imported document metadata. Attacker-controlled fields such as the author meta tag are inserted into a WebVie…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79","CWE-116"],"vendor":"Readwise","product":"Reader","affected":["Reader >= 8.7.2 <= 8.10.1"],"published":"2026-09-25","updated":"2026-09-25","sourceUpdated":"2026-09-25T17:17:07.657","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-18311","references":[{"url":"https://kb.cert.org/vuls/id/699627","label":"cret@cert.org"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-25T16:58:10.634438Z"},"ingestedAt":"2026-09-25T17:13:14.011Z","slug":"CVE-2026-18311","body":"## Overview\n\nReadwise Reader for Android contains a cross-site scripting vulnerability due to missing HTML sanitization in its processing of imported document metadata. Attacker-controlled fields such as the author meta tag are inserted into a WebView via innerHTML, enabling stored XSS that executes on synced devices when the malicious document is opened.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}