Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: koodo-reader

Found 4 matching suggestions

View:
Compact
Detailed
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-18311
6.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 8 hours ago by @Scrumplex Activity log
  • Created suggestion
  • @Scrumplex dismissed (not in Nixpkgs)
CVE-2026-18311

Readwise Reader for Android contains a cross-site scripting vulnerability due to missing HTML sanitization in its processing of imported document metadata. Attacker-controlled fields such as the author meta tag are inserted into a WebView via innerHTML, enabling stored XSS that executes on synced devices when the malicious document is opened.

Affected products

Reader
  • =<8.10.1

Matching in nixpkgs

pkgs.reader

Lightweight tool offering better readability of web pages on the CLI

  • nixos-unstable -
    • nixos-unstable-small 0.6.0
  • nixos-26.05 -
    • nixos-26.05-small 0.5.0

pkgs.xreader

Document viewer capable of displaying multiple and single page document formats like PDF and Postscript

  • nixos-unstable -
    • nixos-unstable-small 4.6.7
  • nixos-26.05 -
    • nixos-26.05-small 4.6.5

pkgs.koreader

Ebook reader application supporting PDF, DjVu, EPUB, FB2 and many more formats, running on Cervantes, Kindle, Kobo, PocketBook and Android devices

  • nixos-unstable -
  • nixos-26.05 -

pkgs.yacreader

Comic reader for cross-platform reading and managing your digital comic collection

  • nixos-unstable -
  • nixos-26.05 -

pkgs.coolreader

Cross platform open source e-book reader

  • nixos-unstable -
  • nixos-26.05 -

pkgs.rfc-reader

RFC viewer with TUI

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ubi_reader

Python scripts capable of extracting and analyzing the contents of UBI and UBIFS images

  • nixos-unstable -
  • nixos-26.05 -

pkgs.mangareader

Qt manga reader for local files

  • nixos-unstable -
    • nixos-unstable-small 2.5.1
  • nixos-26.05 -
    • nixos-26.05-small 2.5.0

pkgs.guile-reader

Simple framework for building readers for GNU Guile

  • nixos-unstable -
    • nixos-unstable-small 0.6.3
  • nixos-26.05 -
    • nixos-26.05-small 0.6.3

pkgs.koodo-reader

Cross-platform ebook reader

  • nixos-unstable -
    • nixos-unstable-small 2.3.4
  • nixos-26.05 -
    • nixos-26.05-small 2.3.4

pkgs.raven-reader

Open source desktop news reader with flexible settings to optimize your experience

  • nixos-unstable -
  • nixos-26.05 -

pkgs.fluent-reader

Modern desktop RSS reader built with Electron, React, and Fluent UI

  • nixos-unstable -
    • nixos-unstable-small 1.2.2
  • nixos-26.05 -
    • nixos-26.05-small 1.2.2

pkgs.haskellPackages.hreader

Generalization of MonadReader and ReaderT using hset

  • nixos-unstable -
    • nixos-unstable-small 1.1.1
  • nixos-26.05 -
    • nixos-26.05-small 1.1.1

Package maintainers

Untriaged
Permalink CVE-2026-18312
6.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 13 hours ago Activity log
  • Created suggestion
CVE-2026-18312

Readwise Reader for Android constructs URLs in its WebView using attacker-controlled metadata without proper encoding or escaping. The application interpolates untrusted values directly into URL strings and inserts them into the DOM via innerHTML. Because the interpolation occurs without HTML or JavaScript context encoding, a crafted metadata value can break out of the intended URL structure and inject script content. An attacker could supply a document containing malicious metadata that, once synchronized to an Android device and rendered in the Reader WebView, results in execution of injected script content, enabling stored cross-site scripting (XSS)

Affected products

Reader
  • =<8.10.1

Matching in nixpkgs

pkgs.reader

Lightweight tool offering better readability of web pages on the CLI

  • nixos-unstable -
    • nixos-unstable-small 0.6.0
  • nixos-26.05 -
    • nixos-26.05-small 0.5.0

pkgs.xreader

Document viewer capable of displaying multiple and single page document formats like PDF and Postscript

  • nixos-unstable -
    • nixos-unstable-small 4.6.7
  • nixos-26.05 -
    • nixos-26.05-small 4.6.5

pkgs.koreader

Ebook reader application supporting PDF, DjVu, EPUB, FB2 and many more formats, running on Cervantes, Kindle, Kobo, PocketBook and Android devices

  • nixos-unstable -
  • nixos-26.05 -

pkgs.yacreader

Comic reader for cross-platform reading and managing your digital comic collection

  • nixos-unstable -
  • nixos-26.05 -

pkgs.coolreader

Cross platform open source e-book reader

  • nixos-unstable -
  • nixos-26.05 -

pkgs.rfc-reader

RFC viewer with TUI

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ubi_reader

Python scripts capable of extracting and analyzing the contents of UBI and UBIFS images

  • nixos-unstable -
  • nixos-26.05 -

pkgs.mangareader

Qt manga reader for local files

  • nixos-unstable -
    • nixos-unstable-small 2.5.1
  • nixos-26.05 -
    • nixos-26.05-small 2.5.0

pkgs.guile-reader

Simple framework for building readers for GNU Guile

  • nixos-unstable -
    • nixos-unstable-small 0.6.3
  • nixos-26.05 -
    • nixos-26.05-small 0.6.3

pkgs.koodo-reader

Cross-platform ebook reader

  • nixos-unstable -
    • nixos-unstable-small 2.3.4
  • nixos-26.05 -
    • nixos-26.05-small 2.3.4

pkgs.raven-reader

Open source desktop news reader with flexible settings to optimize your experience

  • nixos-unstable -
  • nixos-26.05 -

pkgs.fluent-reader

Modern desktop RSS reader built with Electron, React, and Fluent UI

  • nixos-unstable -
    • nixos-unstable-small 1.2.2
  • nixos-26.05 -
    • nixos-26.05-small 1.2.2

pkgs.haskellPackages.hreader

Generalization of MonadReader and ReaderT using hset

  • nixos-unstable -
    • nixos-unstable-small 1.1.1
  • nixos-26.05 -
    • nixos-26.05-small 1.1.1

Package maintainers

Untriaged
Permalink CVE-2026-18320
6.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 13 hours ago Activity log
  • Created suggestion
CVE-2026-18320

Readwise Reader for Android uses a sanitize-html configuration that permits all attributes on SVG and PATH elements due to a wildcard attribute rule. This configuration fails to remove script-capable attributes such as event handlers (e.g., 'onload', 'onerror'). An attacker could supply a document containing malicious SVG content that survives sanitization and executes script wher rendered in the Reader WebView, resulting in client-side cross-site scripting (XSS).

Affected products

Reader
  • <8.10.1

Matching in nixpkgs

pkgs.reader

Lightweight tool offering better readability of web pages on the CLI

  • nixos-unstable -
    • nixos-unstable-small 0.6.0
  • nixos-26.05 -
    • nixos-26.05-small 0.5.0

pkgs.xreader

Document viewer capable of displaying multiple and single page document formats like PDF and Postscript

  • nixos-unstable -
    • nixos-unstable-small 4.6.7
  • nixos-26.05 -
    • nixos-26.05-small 4.6.5

pkgs.koreader

Ebook reader application supporting PDF, DjVu, EPUB, FB2 and many more formats, running on Cervantes, Kindle, Kobo, PocketBook and Android devices

  • nixos-unstable -
  • nixos-26.05 -

pkgs.yacreader

Comic reader for cross-platform reading and managing your digital comic collection

  • nixos-unstable -
  • nixos-26.05 -

pkgs.coolreader

Cross platform open source e-book reader

  • nixos-unstable -
  • nixos-26.05 -

pkgs.rfc-reader

RFC viewer with TUI

  • nixos-unstable -
  • nixos-26.05 -

pkgs.ubi_reader

Python scripts capable of extracting and analyzing the contents of UBI and UBIFS images

  • nixos-unstable -
  • nixos-26.05 -

pkgs.mangareader

Qt manga reader for local files

  • nixos-unstable -
    • nixos-unstable-small 2.5.1
  • nixos-26.05 -
    • nixos-26.05-small 2.5.0

pkgs.guile-reader

Simple framework for building readers for GNU Guile

  • nixos-unstable -
    • nixos-unstable-small 0.6.3
  • nixos-26.05 -
    • nixos-26.05-small 0.6.3

pkgs.koodo-reader

Cross-platform ebook reader

  • nixos-unstable -
    • nixos-unstable-small 2.3.4
  • nixos-26.05 -
    • nixos-26.05-small 2.3.4

pkgs.raven-reader

Open source desktop news reader with flexible settings to optimize your experience

  • nixos-unstable -
  • nixos-26.05 -

pkgs.fluent-reader

Modern desktop RSS reader built with Electron, React, and Fluent UI

  • nixos-unstable -
    • nixos-unstable-small 1.2.2
  • nixos-26.05 -
    • nixos-26.05-small 1.2.2

pkgs.haskellPackages.hreader

Generalization of MonadReader and ReaderT using hset

  • nixos-unstable -
    • nixos-unstable-small 1.1.1
  • nixos-26.05 -
    • nixos-26.05-small 1.1.1

Package maintainers

Dismissed
Permalink CVE-2026-55408
8.4 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Active (A)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Active (A)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated 2 months, 2 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed
Koodo Reader: Remote code execution via malicious epub file

Koodo Reader is an ebook reader. In version 2.3.0 and earlier, Koodo Reader is vulnerable to remote code execution through malicious EPUB files because the open-book IPC handler enables nodeIntegrationInSubFrames and EPUB chapter content is rendered with unsanitized innerHTML. An attacker can craft an EPUB book that, when imported and opened by the victim, instantiates a hidden iframe with Node.js API access and executes arbitrary operating system commands with the victim user's privileges. This issue is fixed in version 2.3.1.

Affected products

koodo-reader
  • ==< 2.3.1

Matching in nixpkgs

Current stable branch was never impacted.