CVE-2026-82090

Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM.  JavaScript code can alter the application state via native bridge methods.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-28 05:16

Updated : 2026-09-09 16:04


NVD link : CVE-2026-82090

Mitre link : CVE-2026-82090

CVE.ORG link : CVE-2026-82090


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')