CVE-2026-78325
Received Received - Intake

Cross-Site Scripting in Standard Notes Android App

Vulnerability report for CVE-2026-78325, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-07

Last updated on: 2026-09-07

Assigner: b2fa7fcc-7d08-41f0-853b-11242c5539db

Description

Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a victim imports a crafted .enex or Google Keep HTML file, leading to theft of encryption keys and note data, and arbitrary invocation of native device APIs.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-07
Last Modified
2026-09-07
Generated
2026-09-07
AI Q&A
2026-09-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 13 associated CPEs
Vendor Product Version / Range
standardnotes standard_notes 3.201.24
proton proton_mail *
proton proton_calendar *
proton proton_drive *
proton proton_vpn *
proton proton_pass *
proton proton_wallet *
proton proton_docs *
proton proton_sheets *
proton proton_authenticator *
proton proton_meet *
proton lumo_ai *
proton simple_login *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a cross-site scripting (XSS) flaw in the Evernote and Google Keep note importers of Standard Notes for Android up to version 3.201.24. An attacker can craft a malicious .enex or Google Keep HTML file that, when imported by a victim, executes arbitrary JavaScript in the application context. This allows theft of encryption keys and note data, as well as arbitrary invocation of native device APIs.

Detection Guidance

This vulnerability involves crafted .enex or Google Keep HTML files triggering XSS in Standard Notes for Android. Detection requires inspecting imported files for suspicious JavaScript or HTML payloads. Check application logs for unexpected script execution during note imports. Monitor network traffic for unauthorized data exfiltration attempts from the app.

Impact Analysis

If you use Standard Notes for Android and import a malicious note file, an attacker could steal your encryption keys and access your encrypted notes. They could also trigger native device functions without your permission, potentially compromising your data and device security.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's security requirements for protected health information. Organizations using Standard Notes may face compliance breaches if user data is compromised due to this flaw.

Mitigation Strategies

Update Standard Notes for Android to version 3.201.25 or later. Avoid importing .enex or Google Keep files from untrusted sources. Disable JavaScript in the app if possible. Revoke any exposed encryption keys and review account activity for unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78325. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart