← Vulnerability feed

Vulnerability record · CVE-2026-23483 · published 23 March 2026

CVE-2026-23483: Blinko path traversal vulnerability

Blinko · Blinko

Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the plugin file server endpoint uses join() to concatenate paths but does not verify if the final path is within the plugins directory, leading to path traversal. At time of publication, there are no publicly available patches.

6.9 CVSS 4.0 Medium EPSS 0.77% · top 46.2% CWE-22 · Path traversal
6.9CVSS 4.0 base score
0.77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the plugin file server endpoint uses join() to concatenate paths but does not verify if the final path is within the plugins directory, leading to path traversal. At time of publication, there are no publicly available patches.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-23483 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2026-23882Blinko os command injection vulnerabilityBlinko is an AI-powered card note-taking project. Prior to version 1.8.4, the MCP (Model Context Protocol) server creation function allows specifying…EPSS 0.36%8.2CVE-2026-23482Blinko path traversal vulnerabilityBlinko is an AI-powered card note-taking project. Prior to version 1.8.4, the file server endpoint does not perform permission checks on the temp/ pa…EPSS 1.5%6.9CVE-2026-23488Blinko insecure direct object reference vulnerabilityBlinko is an AI-powered card note-taking project. Prior to version 1.8.4, the /api/v1/comment/create endpoint has an unauthorized access vulnerabilit…EPSS 0.31%6.9CVE-2026-23485Blinko path traversal vulnerabilityBlinko is an AI-powered card note-taking project. Prior to version 1.8.4, the filePath parameter accepts path traversal sequences, allowing enumerati…EPSS 0.30%6.9CVE-2026-23486Blinko information exposure vulnerabilityBlinko is an AI-powered card note-taking project. Prior to version 1.8.4, a publicly accessible endpoint exposes all user information, including user…EPSS 0.71%6.0CVE-2026-23487Blinko insecure direct object reference vulnerabilityBlinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an IDOR vulnerability where user.detail Endpoint Leaks the Superad…EPSS 0.22%5.3CVE-2026-23481Blinko path traversal vulnerabilityBlinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an authenticated arbitrary file write vulnerability in saveAdditio…EPSS 0.38%5.3CVE-2026-23484Blinko path traversal vulnerabilityBlinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the fileName parameter is not filtered, allowing path traversal t…EPSS 0.34%

Source: NIST National Vulnerability Database (record CVE-2026-23483), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.