CVE-2026-31192

Insufficient validation of Chrome extension identifiers in Raindrop.io Bookmark Manager Web App 5.6.76.0 allows attackers to obtain sensitive user data via a crafted request.
Configurations

Configuration 1 (hide)

cpe:2.3:a:raindrop:raindrop:5.6.76.0:*:*:*:*:chrome:*:*

History

12 May 2026, 20:14

Type Values Removed Values Added
First Time Raindrop
Raindrop raindrop
CPE cpe:2.3:a:raindrop:raindrop:5.6.76.0:*:*:*:*:chrome:*:*
References () https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/CORS - () https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/CORS - Technical Description
References () https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Origin - () https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Origin - Technical Description
References () https://github.com/incoggeek/vulnerability-research/tree/master/CVE-2026-31192 - () https://github.com/incoggeek/vulnerability-research/tree/master/CVE-2026-31192 - Third Party Advisory
References () https://support.google.com/chrome_webstore/answer/2664769?hl=en - () https://support.google.com/chrome_webstore/answer/2664769?hl=en - Not Applicable

22 Apr 2026, 19:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CWE CWE-20
CWE-284

22 Apr 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-22 14:16

Updated : 2026-05-12 20:14


NVD link : CVE-2026-31192

Mitre link : CVE-2026-31192

CVE.ORG link : CVE-2026-31192


JSON object : View

Products Affected

raindrop

  • raindrop
CWE
CWE-20

Improper Input Validation

CWE-284

Improper Access Control