Task Management Application Vulnerability in Mindwtr by Dongdongbh
CVE-2026-107857
4.4MEDIUM
What is CVE-2026-107857?
The Mindwtr application, a free offline-first task management tool, has a significant security flaw in its prior versions before 1.1.5. The mobile application inadvertently writes sensitive information, including the Cloud sync bearer token and WebDAV password, to unencrypted AsyncStorage. This exposure allows unauthorized users to retrieve these credentials if they have access to the application database or a compromised device backup. Consequently, this vulnerability can lead to unauthorized access to synchronized tasks and attachments, compromising user privacy and data integrity. The issue has been addressed in version 1.1.5.
Affected Version(s)
Mindwtr < 1.1.5
