{"id":"CVE-2026-18311","published":"2026-09-25T17:17:07.657","lastModified":"2026-09-28T16:31:16.073","description":"Readwise Reader for Android contains a cross-site scripting vulnerability due to missing HTML sanitization in its processing of imported document metadata. Attacker-controlled fields such as the author meta tag are inserted into a WebView via innerHTML, enabling stored XSS that executes on synced devices when the malicious document is opened.","cvssScore":6.1,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://kb.cert.org/vuls/id/699627","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}