CVE-2026-107857
Mindwtr: Cloud token and WebDAV password stored in plaintext on mobile
CVSS Score
4.4
EPSS Score
0.0%
EPSS Percentile
0th
Mindwtr is a free offline-first task management application for desktop and mobile. Prior to 1.1.5, the mobile application writes the Cloud sync bearer token and WebDAV password to unencrypted AsyncStorage under @mindwtr_cloud_token and @mindwtr_webdav_password. A party with access to the application database or an exposed device backup can recover these credentials and use them to access the user's synchronized tasks and attachments. This issue is fixed in version 1.1.5.
| CWE | CWE-312 CWE-522 |
| Vendor | dongdongbh |
| Product | mindwtr |
| Published | Oct 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for dongdongbh mindwtr
Be the first to know when new medium vulnerabilities affecting dongdongbh mindwtr are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
dongdongbh / Mindwtr
< 1.1.5