{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-82642", "assignerOrgId": "48a46f29-ae42-4e1d-90dd-c1676c1e5e6d", "state": "PUBLISHED", "assignerShortName": "JFROG", "dateReserved": "2026-08-30T13:32:39.506Z", "datePublished": "2026-08-30T13:44:34.109Z", "dateUpdated": "2026-08-30T13:44:34.109Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "48a46f29-ae42-4e1d-90dd-c1676c1e5e6d", "shortName": "JFROG", "dateUpdated": "2026-08-30T13:44:34.109Z" }, "title": "Readest: unsanitized iframe srcdoc attribute in the EPUB sanitizer can lead to arbitrary code execution", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-79", "description": "CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')", "type": "CWE" } ] } ], "affected": [ { "vendor": "readest", "product": "readest", "platforms": [ "Windows", "macOS", "Linux" ], "collectionURL": "https://github.com/readest/readest", "repo": "https://github.com/readest/readest", "versions": [ { "status": "affected", "version": "0", "lessThan": "0.11.16", "versionType": "semver" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized with DOMPurify using a configuration that forbade only the