CVE-2026-78325
Dashboard / Vulnerabilities / CVE-2026-78325
CVE-2026-78325
Summary: XSS in Standard Notes on Android via Malicious Google Keep and Evernote HTML Import
Details: Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a victim imports a crafted .enex or Google Keep HTML file, leading to theft of encryption keys and note data, and arbitrary invocation of native device APIs.
References: https://github.com/standardnotes/app/compare/%40standardnotes/desktop%403.201.24...%40standardnotes/desktop%403.201.25, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78325.json, https://nvd.nist.gov/vuln/detail/CVE-2026-78325, https://proton.me/security/security-advisories
Affected packages
Package
Name:
Purl:
