CISA and Readwise Reader Android report multiple stored XSS vulnerabilities
52nd article in the last 90 days, one of 613 articles referencing Cybersecurity and Infrastructure Security Agency (CISA). Previous coverage: CISA issues update on unauthenticated ViewSonic vCast flaws (Sep 2026).
Companies mentioned
Best suited for
- Seniority
- Analyst
- Job function
- Cybersecurity / Security Analyst
- Persona
- Security Operations Leader
- Buyer role
- Technical Implementer / Administrator
- Buyer journey
- Post Buy
- Adoption curve
- Early Majority
- Technology maturity
- Established Technology
- Industry
- Information Technology / Cybersecurity / Exposure, Risk & Governance / Vulnerability Management & Attack Surface Management
Our classification, not the publisher's statement. Best suited for, not only for.
Readwise Reader for Android version 8.7.2 contains multiple stored cross-site scripting (XSS) vulnerabilities. An attacker who can supply malicious documents or metadata that bypasses sanitization could execute arbitrary JavaScript in the application’s WebView context, affecting the confidentiality and integrity of user data stored and rendered by the app.
The advisory lists three XSS issues. CVE-2026-18311 affects the header rendering component and involves insufficient HTML escaping for metadata fields such as 'doc.author' and 'doc.title', enabling scripts to be stored in a user’s library and synchronized to Android devices for execution in the WebView. CVE-2026-18312 affects WebView URL construction logic for X (formerly Twitter) video fallback and iOS paywall messages, where improper escaping of URL metadata before interpolation into href attributes allows user-controlled values to break out of the URL structure and inject script elements into the DOM via innerHTML. CVE-2026-18320 affects the article body sanitization component, where the sanitize-html configuration includes a wildcard attribute rule that permits all attributes on SVG and PATH elements, allowing script-capable attributes such as onload and onerror to bypass sanitization.
Because the crafted documents or markup bypass sanitization and are stored in user libraries, each vulnerability enables stored XSS after documents are synchronized and rendered in the Reader WebView. CVE-2026-18311 and CVE-2026-18312 are triggered through poisoned metadata, while CVE-2026-18320 is triggered through malicious SVG markup.
The vendor could not be reached to coordinate the issue. Users are instructed to apply vendor updates when available, keep Readwise Reader updated through the Google Play Store, and note that version 8.10.1 includes a patch that addresses the sanitizer-wildcard issue. The guidance also says to exercise caution when adding content from untrusted sources to the reading library and to consider manually reviewing document metadata before saving articles.
These vulnerabilities were reported by Zampier Zago (FUNFACTOR1). The document was written by Alex Lewis. The advisory includes a reference set of CVE IDs for CVE-2026-18311, CVE-2026-18312, and CVE-2026-18320, with publication dates listed as 2026-09-25 and last updated as 2026-09-25 16:59 UTC.
Blog post, originally published by Alex Lewis at kb.cert.org.