Description
Mindwtr is a free offline-first task management application for desktop and mobile. Prior to 1.1.5, the mobile application writes the Cloud sync bearer token and WebDAV password to unencrypted AsyncStorage under @mindwtr_cloud_token and @mindwtr_webdav_password. A party with access to the application database or an exposed device backup can recover these credentials and use them to access the user's synchronized tasks and attachments. This issue is fixed in version 1.1.5.
Published: 2026-10-09
Score: 4.4 Medium
EPSS: n/a
KEV: No
Impact: Data Leakage via Plaintext Credentials
Action: Apply Patch
AI Analysis

Impact

The flaw causes the mobile application to write the Cloud sync bearer token and the WebDAV password to unencrypted AsyncStorage under the keys @mindwtr_cloud_token and @mindwtr_webdav_password. An adversary who can read the application database or obtain a device backup can recover these credentials and gain unauthorized access to the user's synchronized tasks and attachments, effectively allowing data leakage and potential session hijacking.

Affected Systems

The vulnerability affects the Mindwtr mobile application of the vendor dongdongbh, specifically all releases prior to version 1.1.5. Users running these earlier releases should consider their mobile devices, backups, and any local storage as potential vectors for credential compromise.

Risk and Exploitability

The CVSS score is 4.4, indicating moderate severity, yet the EPSS score is not available, leaving the exact exploit probability uncertain. The vulnerability is not listed in the CISA KEV catalog. Attackers need local device access or the ability to access an exposed backup; from there the plaintext token and password are immediately usable to authenticate to the user’s task synchronization services and WebDAV endpoint.

Generated by OpenCVE AI on October 9, 2026 at 21:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Mindwtr mobile application to version 1.1.5 or later to remove plaintext storage of credentials
  • If upgrading is not immediately possible, ensure that device backups are encrypted and access to the mobile device is tightly controlled to prevent unauthorized database reads
  • Consider reconfiguring the application or manually removing the @mindwtr_cloud_token and @mindw_webdav_password entries from AsyncStorage to mitigate credential exposure

Generated by OpenCVE AI on October 9, 2026 at 21:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 20:45:00 +0000

Type Values Removed Values Added
Description Mindwtr is a free offline-first task management application for desktop and mobile. Prior to 1.1.5, the mobile application writes the Cloud sync bearer token and WebDAV password to unencrypted AsyncStorage under @mindwtr_cloud_token and @mindwtr_webdav_password. A party with access to the application database or an exposed device backup can recover these credentials and use them to access the user's synchronized tasks and attachments. This issue is fixed in version 1.1.5.
Title Mindwtr: Cloud token and WebDAV password stored in plaintext on mobile
Weaknesses CWE-312
CWE-522
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T20:33:19.334Z

Reserved: 2026-10-08T22:34:49.292Z

Link: CVE-2026-107857

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T21:17:03.550

Modified: 2026-10-09T21:17:03.550

Link: CVE-2026-107857

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T21:30:12Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information

  • CWE-522

    Insufficiently Protected Credentials