Cross-Site Scripting Flaw in Readwise Reader for Android by Readwise
CVE-2026-18311
6.1MEDIUM
What is CVE-2026-18311?
Readwise Reader for Android is susceptible to a cross-site scripting vulnerability due to insufficient HTML sanitization when processing imported document metadata. This flaw allows attacker-controlled content, such as the author meta tag, to be injected into a WebView via innerHTML. Consequently, this could enable stored XSS attacks, which may execute when a user opens the compromised document on their synced devices, posing a significant risk to users.
Affected Version(s)
Reader 8.7.2 <= 8.10.1
