CVE-2026-78325
6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P
Summary
Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a victim imports a crafted .enex or Google Keep HTML file, leading to theft of encryption keys and note data, and arbitrary invocation of native device APIs.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Standard Notes | Standard Notes | 0 <= v3.201.24 | affected |
Weaknesses
- CWE-79: CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')
References
- https://proton.me/security/security-advisories
- https://github.com/standardnotes/app/compare/%40standardnotes/desktop%403.201.24…%40standardnotes/desktop%403.201.25
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.