Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM. JavaScript code can alter the application state via native bridge methods.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-28 05:16
Updated : 2026-09-09 16:04
NVD link : CVE-2026-82090
Mitre link : CVE-2026-82090
CVE.ORG link : CVE-2026-82090
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
