CVE-2026-107857 Mindwtr 移动端敏感信息明文存储漏洞
影响攻击者可读取设备备份获取同步凭据,访问用户任务与附件
Mindwtr 是一款离线优先的桌面与移动端任务管理应用。在 1.1.5 版本之前,其移动应用将 Cloud 同步 bearer token 与 WebDAV 密码以明文形式写入未加密的 AsyncStorage。该问题已在 1.1.5 版本中修复。
影响范围
Mindwtr 移动应用 1.1.5 之前的版本。
漏洞详情
漏洞类型为敏感信息明文存储(CWE-312)。成因是应用将 @mindwtr_cloud_token 和 @mindwtr_webdav_password 直接写入未加密的 AsyncStorage,未做加密或系统安全存储保护。任何能访问应用数据库或设备备份的一方均可读取这些凭据,进而访问用户同步的任务与附件。
利用条件与风险
利用前提是攻击者能获取应用数据库或设备备份(如物理接触、备份泄露)。CVSS 4.4 属中危,实战中可导致同步数据与附件被未授权访问。
修复建议
官方已在 1.1.5 版本修复,建议升级至 1.1.5 或更高版本;临时缓解措施暂无公开信息。
Mindwtr is a free offline-first task management application for desktop and mobile. Prior to 1.1.5, the mobile application writes the Cloud sync bearer token and WebDAV password to unencrypted AsyncStorage under @mindwtr_cloud_token and @mindwtr_webdav_password. A party with access to the application database or an exposed device backup can recover these credentials and use them to access the user’s synchronized tasks and attachments. This issue is fixed in version 1.1.5.