CVE-2026-78325

Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a victim imports a crafted .enex or Google Keep HTML file, leading to theft of encryption keys and note data, and arbitrary invocation of native device APIs.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-07 12:17

Updated : 2026-09-09 15:52


NVD link : CVE-2026-78325

Mitre link : CVE-2026-78325

CVE.ORG link : CVE-2026-78325


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')