🚨 CVE-2026-78325
Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the application context when a victim imports a crafted .enex or Google Keep HTML file, leading to theft of encryption keys and note data, and arbitrary invocation of native device APIs.
🎖@cveNotify

GitHub
Comparing @standardnotes/[email protected]...@standardnotes/[email protected] · standardnotes/app
Think fearlessly with end-to-end encrypted notes and files. For issues, visit https://standardnotes.com/forum or https://standardnotes.com/help. - Comparing @standardnotes/[email protected]...@stand...
September 7, 2026 13