Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107857— Mindwtr: Cloud token and WebDAV password stored in plaintext on mobile

Quick assessment

Affected
dongdongbh Mindwtr
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Mindwtr 是一款支持离线使用的免费任务管理应用,适用于桌面端和移动端。在 1.1.5 版本之前,该移动应用将云同步的 Bearer Token 和 WebDAV 密码以明文形式存储在未加密的 AsyncStorage 中,键名分别为 @mindwtr_cloud_token 和 @mindwtr_webdav_password。拥有应用程序数据库访问权限或能够获取设备备份信息的攻击者可以恢复这些凭据,并利用它们访问用户同步的任务和附件。此问题已在 1.1.5 版本中得到修复。

CVSS 4.4 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107857

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Mindwtr: Cloud token and WebDAV password stored in plaintext on mobile
Source: CVE Program / CVE List V5
Vulnerability Description
Mindwtr is a free offline-first task management application for desktop and mobile. Prior to 1.1.5, the mobile application writes the Cloud sync bearer token and WebDAV password to unencrypted AsyncStorage under @mindwtr_cloud_token and @mindwtr_webdav_password. A party with access to the application database or an exposed device backup can recover these credentials and use them to access the user's synchronized tasks and attachments. This issue is fixed in version 1.1.5.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
敏感数据的明文存储
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
dongdongbh Mindwtr < 1.1.5 -

II. Public POCs for CVE-2026-107857

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107857

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-107857 (1)

Proof of Concept for CVE-2026-107857 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-107857

No comments yet


Leave a comment