PatchSiren

readest CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH readest CVE published 2026-08-30

CVE-2026-82642

The Readest e-book reader, built on Tauri, contains a vulnerability (CVE-2026-82642) that allows for arbitrary code execution via crafted EPUB content. This vulnerability is caused by inadequate sanitization of EPUB chapter HTML, specifically permitting an attacker to embed a complete HTML document containing a script tag inside an iframe's srcdoc attribute. The content iframe is configured with sandbox=' [truncated]