← Vulnerability feed

Vulnerability record · CVE-2026-23482 · published 23 March 2026

CVE-2026-23482: Blinko path traversal vulnerability

Blinko · Blinko

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the file server endpoint does not perform permission checks on the temp/ path and does not filter path traversal sequences, allowing unauthorized attackers to read arbitrary files on the server. When scheduled backup tasks are enabled, attackers can read backup files to obtain all user notes and user TOKENS. This issue has been patched in version 1.8.4.

8.2 CVSS 4.0 High EPSS 1.5% · top 26.4% CWE-22 · Path traversal
8.2CVSS 4.0 base score
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the file server endpoint does not perform permission checks on the temp/ path and does not filter path traversal sequences, allowing unauthorized attackers to read arbitrary files on the server. When scheduled backup tasks are enabled, attackers can read backup files to obtain all user notes and user TOKENS. This issue has been patched in version 1.8.4.

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-23482 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2026-23882Blinko os command injection vulnerabilityBlinko is an AI-powered card note-taking project. Prior to version 1.8.4, the MCP (Model Context Protocol) server creation function allows specifying…EPSS 0.36%6.9CVE-2026-23488Blinko insecure direct object reference vulnerabilityBlinko is an AI-powered card note-taking project. Prior to version 1.8.4, the /api/v1/comment/create endpoint has an unauthorized access vulnerabilit…EPSS 0.31%6.9CVE-2026-23483Blinko path traversal vulnerabilityBlinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the plugin file server endpoint uses join() to concatenate paths …EPSS 0.77%6.9CVE-2026-23485Blinko path traversal vulnerabilityBlinko is an AI-powered card note-taking project. Prior to version 1.8.4, the filePath parameter accepts path traversal sequences, allowing enumerati…EPSS 0.30%6.9CVE-2026-23486Blinko information exposure vulnerabilityBlinko is an AI-powered card note-taking project. Prior to version 1.8.4, a publicly accessible endpoint exposes all user information, including user…EPSS 0.71%6.0CVE-2026-23487Blinko insecure direct object reference vulnerabilityBlinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an IDOR vulnerability where user.detail Endpoint Leaks the Superad…EPSS 0.22%5.3CVE-2026-23481Blinko path traversal vulnerabilityBlinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an authenticated arbitrary file write vulnerability in saveAdditio…EPSS 0.38%5.3CVE-2026-23484Blinko path traversal vulnerabilityBlinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the fileName parameter is not filtered, allowing path traversal t…EPSS 0.34%

Source: NIST National Vulnerability Database (record CVE-2026-23482), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.