๐Ÿ” CVE Alert

CVE-2026-107857

MEDIUM 4.4

Mindwtr: Cloud token and WebDAV password stored in plaintext on mobile

CVSS Score
4.4
EPSS Score
0.0%
EPSS Percentile
0th

Mindwtr is a free offline-first task management application for desktop and mobile. Prior to 1.1.5, the mobile application writes the Cloud sync bearer token and WebDAV password to unencrypted AsyncStorage under @mindwtr_cloud_token and @mindwtr_webdav_password. A party with access to the application database or an exposed device backup can recover these credentials and use them to access the user's synchronized tasks and attachments. This issue is fixed in version 1.1.5.

CWE CWE-312 CWE-522
Vendor dongdongbh
Product mindwtr
Published Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for dongdongbh mindwtr

Be the first to know when new medium vulnerabilities affecting dongdongbh mindwtr are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

dongdongbh / Mindwtr
< 1.1.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/dongdongbh/Mindwtr/security/advisories/GHSA-8x25-76x5-jgmr github.com: https://github.com/dongdongbh/Mindwtr/commit/b30f568aab753c13d11943452b32f5520712aedb github.com: https://github.com/dongdongbh/Mindwtr/releases/tag/v1.1.5