Executive brief
Standard Notes is a privacy-focused note-taking application for Android. A cross-site scripting vulnerability in the Evernote and Google Keep note importers allows an attacker to execute malicious code when a user imports a crafted note file, potentially exposing encryption keys, stealing notes, and executing arbitrary device functions.
Technical details
The vulnerability is a cross-site scripting (XSS) flaw in Standard Notes' Evernote (.enex) and Google Keep HTML note importers. The importers fail to properly sanitize user-controlled input from crafted import files, allowing arbitrary JavaScript to execute within the application context. An attacker can craft a malicious .enex or Google Keep HTML file; when a victim imports this file, the injected JavaScript runs with access to the app's encryption keys, note data, and native device APIs. The fix was released in version 3.201.25.
Affected products
- Standard Notes Standard Notes through 3.201.24
Timeline
- 2026-09-07: disclosed
- 2026-04-08: patched: Fix released in version 3.201.25