VU#699627: Readwise Reader for Android, version 8.7.2, contains multiple XSS vulnerabilities

What happened
Overview Three cross-site scripting (XSS) vulnerabilities identified in Readwise Reader for Android version 8.7.2 are disclosed. It is available on multiple platforms including Android and can synchronize content across devices.
An attacker with the ability to craft malicious documents or metadata can exploit these vulnerabilities by supplying poisoned content that bypasses sanitization. Description Readwise Reader from Readwise is designed to provide a unified read-it-later service that helps individuals collect and organize articles, newsletters, videos, and other content of interest into a single reading interface. CVE-2026-18311 (the public catalogue number for a specific software flaw) : A stored cross-site scripting (XSS) vulnerability in the header rendering component in Readwise Reader for Android version 8.7.2 allows remote attackers to execute arbitrary JavaScript via crafted document metadata fields.
Sources & evidence
- CERT/CC Vulnerability Notes Primary / official
VU#699627: Readwise Reader for Android, version 8.7.2, contains multiple XSS vulnerabilities โ
https://kb.cert.org/vuls/id/699627