Description
Insufficient validation of Chrome extension identifiers in Raindrop.io Bookmark Manager Web App 5.6.76.0 allows attackers to obtain sensitive user data via a crafted request.
References
https://developer.mozilla.org/en-US/docs/Web/HTTP/Guides/CORS
Technical Description
https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Origin
Technical Description
https://github.com/incoggeek/vulnerability-research/tree/master/CVE-2026-31192
Third Party Advisory
Weaknesses
134c704f-9b21-4f2e-91b3-4a467353bcc0
Secondary
CWE-20CWE-284
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
6.5 · Medium
Information
Source identifier
Vulnerability status
Analyzed
Published
2026-04-22T14:16:36.420Z
5 months agoLast modified
2026-06-17T10:33:25.687Z
3 months ago