CVE-2026-31192 is an identifier validation flaw in Raindrop.io Bookmark Manager Web App version 5.6.76.0 that permits attackers to extract sensitive user data through specially crafted requests exploiting insufficient validation of Chrome extension identifiers. The vulnerability carries a CVSS v3.1 severity score of 6.5 (Medium) with a network-based attack vector requiring no authentication or user interaction, though with low attack complexity. While the vulnerability poses a moderate confidentiality and integrity risk, it does not impact availability. There is no current evidence of active exploitation in the wild, nor is it listed on the Known Exploited Vulnerabilities (KEV) catalog, indicating limited community attention and no widely available exploit code at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.6.76.0CPE matchmatch criteria | cpe:2.3:a:raindrop:raindrop:5.6.76.0:*:*:*:*:chrome:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.