Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute… (CVE-2026-78325)
A cross-site scripting (XSS) vulnerability exists in the Evernote and Google Keep note importers in Standard Notes for Android versions through 3.201.24. This flaw allows an attacker to execute arbitrary JavaScript within the application context when a victim imports a specially crafted .enex or Google Keep HTML file. Exploitation can lead to theft of encryption keys and note data, as well as arbitrary invocation of native device APIs.
AI Analysis
Technical Summary
The vulnerability identified as CVE-2026-78325 is a cross-site scripting issue in the Evernote and Google Keep note importers of Standard Notes for Android up to version 3.201.24. When a user imports a maliciously crafted .enex or Google Keep HTML file, arbitrary JavaScript can be executed in the app context. This can result in the compromise of sensitive data such as encryption keys and note contents, and may allow attackers to invoke native device APIs without authorization. The vulnerability is categorized under CWE-79 (Improper Neutralization of Input During Web Page Generation). No patch or remediation details are currently provided.
Potential Impact
Successful exploitation of this vulnerability can lead to the theft of encryption keys and note data stored within the application. Additionally, attackers may invoke native device APIs arbitrarily, potentially leading to further compromise of the device or user data. The vulnerability requires user interaction (importing a crafted file) and local access (application context), limiting remote exploitation. The severity is assessed as medium based on the potential data theft and API invocation capabilities.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid importing .enex or Google Keep HTML files from untrusted sources. Monitoring vendor channels for updates and applying any forthcoming patches promptly is recommended.
Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute… (CVE-2026-78325)
Description
A cross-site scripting (XSS) vulnerability exists in the Evernote and Google Keep note importers in Standard Notes for Android versions through 3.201.24. This flaw allows an attacker to execute arbitrary JavaScript within the application context when a victim imports a specially crafted .enex or Google Keep HTML file. Exploitation can lead to theft of encryption keys and note data, as well as arbitrary invocation of native device APIs.
CVSS v4.0
Affected software
pkg:github/standardnotes/appRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability identified as CVE-2026-78325 is a cross-site scripting issue in the Evernote and Google Keep note importers of Standard Notes for Android up to version 3.201.24. When a user imports a maliciously crafted .enex or Google Keep HTML file, arbitrary JavaScript can be executed in the app context. This can result in the compromise of sensitive data such as encryption keys and note contents, and may allow attackers to invoke native device APIs without authorization. The vulnerability is categorized under CWE-79 (Improper Neutralization of Input During Web Page Generation). No patch or remediation details are currently provided.
Potential Impact
Successful exploitation of this vulnerability can lead to the theft of encryption keys and note data stored within the application. Additionally, attackers may invoke native device APIs arbitrarily, potentially leading to further compromise of the device or user data. The vulnerability requires user interaction (importing a crafted file) and local access (application context), limiting remote exploitation. The severity is assessed as medium based on the potential data theft and API invocation capabilities.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid importing .enex or Google Keep HTML files from untrusted sources. Monitoring vendor channels for updates and applying any forthcoming patches promptly is recommended.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-3799-7g8h-9xh6
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-78325"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a9ee197acd9273b49e68c59
Added to database: 09/07/2026, 16:08:55 UTC
Last enriched: 09/07/2026, 16:12:31 UTC
Last updated: 09/08/2026, 03:14:39 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.