Readwise Reader 的 Android 版本中,sanitize-html 配置由于使用了通配符属性规则,允许在 SVG 和 PATH 元素上保留所有属性。该配置未能移除具备脚本执行能力的属性(如事件处理程序属性,例如 'onload'、'onerror')。攻击者可以提交包含恶意 SVG 内容的文档,该文档在通过sanitize-html 处理后仍保留可执行脚本的属性,并在 Reader 的 WebView 中渲染时执行脚本,从而导致客户端侧的跨站脚本攻击(XSS)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18311 | CVE-2026-18311 | |
| CVE-2026-18312 | CVE-2026-18312 |
No comments yet