Skip to main content

CISA and Readwise Reader Android report multiple stored XSS vulnerabilities

52nd article in the last 90 days, one of 613 articles referencing Cybersecurity and Infrastructure Security Agency (CISA). Previous coverage: CISA issues update on unauthenticated ViewSonic vCast flaws (Sep 2026).

Companies mentioned

Best suited for

Seniority
Analyst
Job function
Cybersecurity / Security Analyst
Persona
Security Operations Leader
Buyer role
Technical Implementer / Administrator
Buyer journey
Post Buy
Adoption curve
Early Majority
Technology maturity
Established Technology
Industry
Information Technology / Cybersecurity / Exposure, Risk & Governance / Vulnerability Management & Attack Surface Management

Our classification, not the publisher's statement. Best suited for, not only for.

Readwise Reader for Android version 8.7.2 contains multiple stored cross-site scripting (XSS) vulnerabilities. An attacker who can supply malicious documents or metadata that bypasses sanitization could execute arbitrary JavaScript in the application’s WebView context, affecting the confidentiality and integrity of user data stored and rendered by the app.

The advisory lists three XSS issues. CVE-2026-18311 affects the header rendering component and involves insufficient HTML escaping for metadata fields such as 'doc.author' and 'doc.title', enabling scripts to be stored in a user’s library and synchronized to Android devices for execution in the WebView. CVE-2026-18312 affects WebView URL construction logic for X (formerly Twitter) video fallback and iOS paywall messages, where improper escaping of URL metadata before interpolation into href attributes allows user-controlled values to break out of the URL structure and inject script elements into the DOM via innerHTML. CVE-2026-18320 affects the article body sanitization component, where the sanitize-html configuration includes a wildcard attribute rule that permits all attributes on SVG and PATH elements, allowing script-capable attributes such as onload and onerror to bypass sanitization.

Because the crafted documents or markup bypass sanitization and are stored in user libraries, each vulnerability enables stored XSS after documents are synchronized and rendered in the Reader WebView. CVE-2026-18311 and CVE-2026-18312 are triggered through poisoned metadata, while CVE-2026-18320 is triggered through malicious SVG markup.

The vendor could not be reached to coordinate the issue. Users are instructed to apply vendor updates when available, keep Readwise Reader updated through the Google Play Store, and note that version 8.10.1 includes a patch that addresses the sanitizer-wildcard issue. The guidance also says to exercise caution when adding content from untrusted sources to the reading library and to consider manually reviewing document metadata before saving articles.

These vulnerabilities were reported by Zampier Zago (FUNFACTOR1). The document was written by Alex Lewis. The advisory includes a reference set of CVE IDs for CVE-2026-18311, CVE-2026-18312, and CVE-2026-18320, with publication dates listed as 2026-09-25 and last updated as 2026-09-25 16:59 UTC.

Blog post, originally published by Alex Lewis at kb.cert.org.

Structured data (JSON-LD)

The schema.org markup this page publishes for search engines and AI agents, exactly as they read it.

[
  {
    "@context": "https://schema.org",
    "@id": "https://decisioninsights.ai/#website",
    "@type": "WebSite",
    "name": "Decision Insights",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://decisioninsights.ai/search/?q={search_term_string}&submit=1"
      }
    },
    "publisher": {
      "@id": "https://decisioninsights.ai/#organization"
    },
    "url": "https://decisioninsights.ai"
  },
  {
    "@context": "https://schema.org",
    "@id": "https://decisioninsights.ai/#organization",
    "@type": "Organization",
    "contactPoint": {
      "@type": "ContactPoint",
      "contactType": "customer support",
      "email": "[email protected]"
    },
    "description": "Decision Insights is a Registry of technology companies, open source projects, and industry terms, built for people and for AI agents that need sourced, structured information.",
    "logo": {
      "@type": "ImageObject",
      "url": "https://wiretap-cdn-assets.nyc3.cdn.digitaloceanspaces.com/decision-insights/[email protected]"
    },
    "name": "Decision Insights",
    "parentOrganization": {
      "@type": "Organization",
      "name": "Wiretap Labs",
      "sameAs": [
        "https://www.linkedin.com/company/wiretap-labs",
        "https://www.crunchbase.com/organization/wiretap-labs"
      ],
      "url": "https://wiretaplabs.com"
    },
    "publishingPrinciples": "https://decisioninsights.ai/standards/",
    "sameAs": [
      "https://www.linkedin.com/company/decisioninsights"
    ],
    "url": "https://decisioninsights.ai"
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "itemListElement": [
      {
        "@type": "ListItem",
        "item": "https://decisioninsights.ai",
        "name": "Decision Insights",
        "position": 1
      },
      {
        "@type": "ListItem",
        "item": "https://decisioninsights.ai/records/",
        "name": "Records",
        "position": 2
      },
      {
        "@type": "ListItem",
        "item": "https://decisioninsights.ai/cisa-and-readwise-reader-android-report-multiple-stored-xss-vulnerabilities/",
        "name": "CISA and Readwise Reader Android report multiple stored XSS vulnerabilities",
        "position": 3
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@id": "https://decisioninsights.ai/cisa-and-readwise-reader-android-report-multiple-stored-xss-vulnerabilities/#blogposting",
    "@type": "BlogPosting",
    "about": {
      "@id": "https://decisioninsights.ai/registry/department-of-homeland-security/cybersecurity-and-infrastructure-security-agency-cisa/#organization",
      "@type": "Organization",
      "mainEntityOfPage": "https://decisioninsights.ai/registry/department-of-homeland-security/cybersecurity-and-infrastructure-security-agency-cisa/",
      "name": "Cybersecurity and Infrastructure Security Agency (CISA)"
    },
    "audience": [
      {
        "@type": "Audience",
        "additionalType": "Seniority",
        "audienceType": "Analyst"
      },
      {
        "@type": "Audience",
        "additionalType": "Job function",
        "audienceType": "Cybersecurity / Security Analyst"
      },
      {
        "@type": "Audience",
        "additionalType": "Persona",
        "audienceType": "Security Operations Leader"
      },
      {
        "@type": "Audience",
        "additionalType": "Buyer role",
        "audienceType": "Technical Implementer / Administrator"
      },
      {
        "@type": "Audience",
        "additionalType": "Adoption curve",
        "audienceType": "Early Majority"
      },
      {
        "@type": "Audience",
        "additionalType": "Technology maturity",
        "audienceType": "Established Technology"
      },
      {
        "@type": "Audience",
        "additionalType": "Industry",
        "audienceType": "Information Technology / Cybersecurity / Exposure, Risk & Governance / Vulnerability Management & Attack Surface Management"
      }
    ],
    "author": {
      "@id": "https://decisioninsights.ai/author/decision-insights-threat-desk/#person",
      "@type": "Person",
      "name": "Decision Insights Threat Desk",
      "url": "https://decisioninsights.ai/author/decision-insights-threat-desk/"
    },
    "dateModified": "2026-09-25T13:49:42-06:00",
    "datePublished": "2026-09-25T13:49:38-06:00",
    "description": "Readwise Reader Android 8.7.2 has stored XSS vulnerabilities involving CVE-2026-18311, CVE-2026-18312, and CVE-2026-18320 and a patch in 8.10.1.",
    "headline": "CISA and Readwise Reader Android report multiple stored XSS vulnerabilities",
    "isBasedOn": {
      "@type": "CreativeWork",
      "author": {
        "@type": "Person",
        "name": "Alex Lewis"
      },
      "sourceOrganization": {
        "@id": "https://decisioninsights.ai/registry/department-of-homeland-security/#organization",
        "@type": "Organization",
        "mainEntityOfPage": "https://decisioninsights.ai/registry/department-of-homeland-security/",
        "name": "Department of Homeland Security"
      },
      "url": "https://kb.cert.org/vuls/id/699627"
    },
    "keywords": [
      "Cross-Site Scripting",
      "Metadata",
      "Vulnerabilities"
    ],
    "mainEntityOfPage": {
      "@id": "https://decisioninsights.ai/cisa-and-readwise-reader-android-report-multiple-stored-xss-vulnerabilities/",
      "@type": "WebPage",
      "sdDatePublished": "2026-09-25",
      "sdPublisher": {
        "@id": "https://decisioninsights.ai/#organization"
      }
    },
    "mentions": [
      {
        "@id": "https://decisioninsights.ai/registry/department-of-homeland-security/cybersecurity-and-infrastructure-security-agency-cisa/#organization",
        "@type": "Organization",
        "mainEntityOfPage": "https://decisioninsights.ai/registry/department-of-homeland-security/cybersecurity-and-infrastructure-security-agency-cisa/",
        "name": "Cybersecurity and Infrastructure Security Agency (CISA)"
      }
    ],
    "publisher": {
      "@id": "https://decisioninsights.ai/#organization"
    }
  },
  {
    "@context": "https://schema.org",
    "@id": "https://decisioninsights.ai/author/decision-insights-threat-desk/#person",
    "@type": "Person",
    "description": "CISA advisories, vendor security bulletins, and CVE disclosures, summarized into sourced briefs. Produced under our Standards & Methodology.",
    "name": "Decision Insights Threat Desk",
    "sameAs": [
      "https://www.linkedin.com/showcase/decisioninsights/"
    ],
    "url": "https://decisioninsights.ai/author/decision-insights-threat-desk/"
  }
]

Is this your company? Get structured data for your own pages