VU#699627: Readwise Reader for Android, version 8.7.2, contains multiple XSS vulnerabilities
Readwise Reader for Android version 8.7.2 contains three stored cross-site scripting (XSS) vulnerabilities. These flaws allow attackers who can supply malicious documents or metadata to execute arbitrary JavaScript within the app's WebView context. The vulnerabilities arise from insufficient sanitization of document metadata fields, improper escaping of URL metadata, and permissive sanitization rules for SVG markup. Exploitation could compromise user data confidentiality and integrity, including access to stored documents, credentials, and session tokens. A patch addressing one of the issues is available in version 8.10.1. Users are advised to update when possible and exercise caution when adding content from untrusted sources.
AI Analysis
Technical Summary
Three stored XSS vulnerabilities (CVE-2026-18311, CVE-2026-18312, CVE-2026-18320) affect Readwise Reader for Android version 8.7.2. CVE-2026-18311 involves insufficient HTML escaping in header rendering metadata fields like 'doc.author' and 'doc.title', allowing script injection in synchronized documents. CVE-2026-18312 concerns improper escaping of URL metadata used in WebView URL construction for X video fallback and iOS paywall messages, enabling script injection via href attributes. CVE-2026-18320 results from a wildcard attribute rule in the sanitize-html configuration permitting script-capable attributes such as onload and onerror on SVG and PATH elements, allowing malicious SVG markup to execute scripts. These vulnerabilities enable attackers who can craft or modify documents accessible to the app to execute arbitrary JavaScript in the WebView context, potentially compromising user data. The vendor was not reachable for coordination, but version 8.10.1 includes a patch for the sanitizer wildcard issue.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary JavaScript within the Readwise Reader Android app's WebView context by supplying malicious document metadata or SVG markup. This can compromise the confidentiality and integrity of user data, including stored documents, credentials, and session tokens. The vulnerabilities are stored XSS, meaning malicious scripts persist in user libraries and synchronize across devices, increasing exposure risk.
Mitigation Recommendations
Users should update Readwise Reader for Android to version 8.10.1 or later, which includes a patch addressing the sanitizer wildcard issue (CVE-2026-18320). Since the vendor could not be reached for coordinated disclosure, users should monitor for further vendor updates that address all identified vulnerabilities. Additionally, users should exercise caution when adding content from untrusted sources and manually review document metadata before saving articles to reduce exposure to malicious content.
VU#699627: Readwise Reader for Android, version 8.7.2, contains multiple XSS vulnerabilities
Description
Readwise Reader for Android version 8.7.2 contains three stored cross-site scripting (XSS) vulnerabilities. These flaws allow attackers who can supply malicious documents or metadata to execute arbitrary JavaScript within the app's WebView context. The vulnerabilities arise from insufficient sanitization of document metadata fields, improper escaping of URL metadata, and permissive sanitization rules for SVG markup. Exploitation could compromise user data confidentiality and integrity, including access to stored documents, credentials, and session tokens. A patch addressing one of the issues is available in version 8.10.1. Users are advised to update when possible and exercise caution when adding content from untrusted sources.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Three stored XSS vulnerabilities (CVE-2026-18311, CVE-2026-18312, CVE-2026-18320) affect Readwise Reader for Android version 8.7.2. CVE-2026-18311 involves insufficient HTML escaping in header rendering metadata fields like 'doc.author' and 'doc.title', allowing script injection in synchronized documents. CVE-2026-18312 concerns improper escaping of URL metadata used in WebView URL construction for X video fallback and iOS paywall messages, enabling script injection via href attributes. CVE-2026-18320 results from a wildcard attribute rule in the sanitize-html configuration permitting script-capable attributes such as onload and onerror on SVG and PATH elements, allowing malicious SVG markup to execute scripts. These vulnerabilities enable attackers who can craft or modify documents accessible to the app to execute arbitrary JavaScript in the WebView context, potentially compromising user data. The vendor was not reachable for coordination, but version 8.10.1 includes a patch for the sanitizer wildcard issue.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary JavaScript within the Readwise Reader Android app's WebView context by supplying malicious document metadata or SVG markup. This can compromise the confidentiality and integrity of user data, including stored documents, credentials, and session tokens. The vulnerabilities are stored XSS, meaning malicious scripts persist in user libraries and synchronize across devices, increasing exposure risk.
Mitigation Recommendations
Users should update Readwise Reader for Android to version 8.10.1 or later, which includes a patch addressing the sanitizer wildcard issue (CVE-2026-18320). Since the vendor could not be reached for coordinated disclosure, users should monitor for further vendor updates that address all identified vulnerabilities. Additionally, users should exercise caution when adding content from untrusted sources and manually review document metadata before saving articles to reduce exposure to malicious content.
Technical Details
- Classification
- {"confidence":0.93,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://kb.cert.org/vuls/id/699627","fetched":true,"fetchedAt":"2026-09-25T16:32:26.896Z","wordCount":696}
Threat ID: 6ab6a21af7a7c54106fff9c7
Added to database: 09/25/2026, 16:32:26 UTC
Last enriched: 09/25/2026, 16:32:31 UTC
Last updated: 09/26/2026, 02:51:29 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.