CVE-2026-78325 PUBLISHED

XSS in Standard Notes on Android via Malicious Google Keep and Evernote HTML Import

Assigner: Proton
Reserved: 24.08.2026 Published: 07.09.2026 Updated: 07.09.2026

Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a victim imports a crafted .enex or Google Keep HTML file, leading to theft of encryption keys and note data, and arbitrary invocation of native device APIs.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P
CVSS Score: 6.9

Product Status

Vendor Standard Notes
Product Standard Notes
Versions Default: unaffected
  • affected from 0 to v3.201.24 (incl.)

Credits

  • Luca Regne, https://regne.me/ finder

References

Problem Types

  • CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') CWE

Impacts

  • CAPEC-63 Cross-Site Scripting (XSS)