{"id":"CVE-2026-82089","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-82089","summary":"The wallabag (aka fr.gaulupeau.apps.InThePoche) application through 2.6.0 for Android allows XSS because /api/entries data is loaded into a WebView.","details":"The wallabag (aka fr.gaulupeau.apps.InThePoche) application through 2.6.0 for Android allows XSS because /api/entries data is loaded into a WebView.","published":"2026-08-28T05:16:47.230","modified":"2026-08-28T05:16:47.230","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/wallabag/android-app/blob/master/app/src/main/java/fr/gaulupeau/apps/Poche/data/StorageHelper.java"},{"type":"WEB","url":"https://github.com/wallabag/android-app/blob/master/app/src/main/java/fr/gaulupeau/apps/Poche/events/EventProcessor.java"},{"type":"WEB","url":"https://github.com/wallabag/android-app/blob/master/app/src/main/java/fr/gaulupeau/apps/Poche/service/workers/ArticleAsFileDownloader.java"},{"type":"WEB","url":"https://github.com/wallabag/android-app/blob/master/app/src/main/java/fr/gaulupeau/apps/Poche/service/workers/ArticleUpdater.java"},{"type":"WEB","url":"https://github.com/wallabag/android-app/blob/master/app/src/main/java/fr/gaulupeau/apps/Poche/ui/ReadArticleActivity.java"},{"type":"WEB","url":"https://github.com/wallabag/wallabag/security/advisories/GHSA-q2g2-www6-wf5h"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-28T05:16:47.230"}}