Cross-Site Scripting Vulnerability in Readwise Reader for Android
CVE-2026-18320

6.1MEDIUM

Key Information:

Vendor

Readwise

Status
Vendor
CVE Published:
25 September 2026

What is CVE-2026-18320?

Readwise Reader for Android contains a security configuration flaw in the sanitize-html function, which allows all attributes on SVG and PATH elements due to a wildcard attribute rule. This oversight fails to effectively eliminate script-capable attributes such as event handlers. As a result, an attacker can craft a document with malicious SVG content that bypasses sanitization, executing potentially harmful scripts when rendered in the Reader's WebView, leading to unauthorized actions and data exposure.

Affected Version(s)

Reader 8.7.2 < 8.10.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.