CVE-2026-78325
Received
Received - Intake
Cross-Site Scripting in Standard Notes Android App
Vulnerability report for CVE-2026-78325, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-07
Last updated on: 2026-09-07
Assigner: b2fa7fcc-7d08-41f0-853b-11242c5539db
Description
Description
Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a victim imports a crafted .enex or Google Keep HTML file, leading to theft of encryption keys and note data, and arbitrary invocation of native device APIs.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| standardnotes | standard_notes | 3.201.24 |
| proton | proton_mail | * |
| proton | proton_calendar | * |
| proton | proton_drive | * |
| proton | proton_vpn | * |
| proton | proton_pass | * |
| proton | proton_wallet | * |
| proton | proton_docs | * |
| proton | proton_sheets | * |
| proton | proton_authenticator | * |
| proton | proton_meet | * |
| proton | lumo_ai | * |
| proton | simple_login | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-79 | The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. |