Cross-Site Scripting Vulnerability in Readwise Reader for Android
CVE-2026-18320
6.1MEDIUM
What is CVE-2026-18320?
Readwise Reader for Android contains a security configuration flaw in the sanitize-html function, which allows all attributes on SVG and PATH elements due to a wildcard attribute rule. This oversight fails to effectively eliminate script-capable attributes such as event handlers. As a result, an attacker can craft a document with malicious SVG content that bypasses sanitization, executing potentially harmful scripts when rendered in the Reader's WebView, leading to unauthorized actions and data exposure.
Affected Version(s)
Reader 8.7.2 < 8.10.1
