PatchSiren

Standard Notes CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Standard Notes CVE published 2026-09-07

CVE-2026-78325

A cross-site scripting vulnerability exists in Standard Notes for Android through 3.201.24, allowing an attacker to execute arbitrary JavaScript when a victim imports a crafted .enex or Google Keep HTML file. This vulnerability can lead to theft of encryption keys and note data, and arbitrary invocation of native device APIs. The Evernote and Google Keep note importers are affected, and defenders should a [truncated]