CVE-2026-31192Disclosure(raindrop / raindrop)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Insufficient validation of Chrome extension identifiers in Raindrop.io Bookmark Manager Web App 5.6.76.0 allows attackers to obtain sensitive user data via a crafted request.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • raindrop

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
raindrop

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-25: 1Technical Details · 2026-04-25: 104-25
Signal classification1 categories
Disclosure
1100.0%
Referenced assets2 URLs
By indicator
Full discourse1 post
  • CVE@CVEnew
    Disclosure

    CVE-2026-31192 Insufficient validation of Chrome extension identifiers in http://Raindrop.io Bookmark Manager Web App 5.6.76.0 allows attackers to obtain sensitive user data via a crafted … https://www.cve.org/CVERecord?id=CVE-2026-31192

    Post summary

    A newly identified vulnerability (CVE-2026-31192) in Raindrop.io Bookmark Manager allows attackers to obtain sensitive user data due to insufficient validation of Chrome extension identifiers.

    00000228
    57.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appraindropraindrop5.6.76.0chrome-

Explore more