CVE-2026-18320 is a client-side cross-site scripting (XSS) vulnerability in Readwise Reader for Android. The vulnerability arises from a sanitize-html configuration that permits all attributes on SVG and PATH elements, allowing script-capable attributes like event handlers to survive sanitization and execute in the Reader WebView. This could enable an attacker to supply malicious SVG content that executes [truncated]
CVE-2026-18312 is a stored cross-site scripting (XSS) vulnerability in Readwise Reader for Android. The application constructs URLs in its WebView using attacker-controlled metadata without proper encoding or escaping, allowing an attacker to inject script content and enabling stored XSS. This vulnerability can be exploited when an attacker supplies a document containing malicious metadata that, once sync [truncated]
Readwise Reader for Android contains a cross-site scripting vulnerability due to missing HTML sanitization in its processing of imported document metadata. Attacker-controlled fields such as the author meta tag are inserted into a WebView via innerHTML, enabling stored XSS that executes on synced devices when the malicious document is opened. The vulnerability allows for stored XSS attacks, which can be e [truncated]