← Vulnerability feed

Vulnerability record · CVE-2026-23484 · published 23 March 2026

CVE-2026-23484: Blinko path traversal vulnerability

Blinko · Blinko

Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the fileName parameter is not filtered, allowing path traversal to write files anywhere on the file system. Moreover, this interface only requires authProcedure (normal user), not superAdminAuthMiddleware. At time of publication, there are no publicly available patches.

5.3 CVSS 4.0 Medium EPSS 0.34% · top 75.6% CWE-22 · Path traversal
5.3CVSS 4.0 base score
0.34%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the fileName parameter is not filtered, allowing path traversal to write files anywhere on the file system. Moreover, this interface only requires authProcedure (normal user), not superAdminAuthMiddleware. At time of publication, there are no publicly available patches.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-23484 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.6CVE-2026-23882Blinko os command injection vulnerabilityBlinko is an AI-powered card note-taking project. Prior to version 1.8.4, the MCP (Model Context Protocol) server creation function allows specifying…EPSS 0.36%8.2CVE-2026-23482Blinko path traversal vulnerabilityBlinko is an AI-powered card note-taking project. Prior to version 1.8.4, the file server endpoint does not perform permission checks on the temp/ pa…EPSS 1.5%6.9CVE-2026-23488Blinko insecure direct object reference vulnerabilityBlinko is an AI-powered card note-taking project. Prior to version 1.8.4, the /api/v1/comment/create endpoint has an unauthorized access vulnerabilit…EPSS 0.31%6.9CVE-2026-23483Blinko path traversal vulnerabilityBlinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the plugin file server endpoint uses join() to concatenate paths …EPSS 0.77%6.9CVE-2026-23485Blinko path traversal vulnerabilityBlinko is an AI-powered card note-taking project. Prior to version 1.8.4, the filePath parameter accepts path traversal sequences, allowing enumerati…EPSS 0.30%6.9CVE-2026-23486Blinko information exposure vulnerabilityBlinko is an AI-powered card note-taking project. Prior to version 1.8.4, a publicly accessible endpoint exposes all user information, including user…EPSS 0.71%6.0CVE-2026-23487Blinko insecure direct object reference vulnerabilityBlinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an IDOR vulnerability where user.detail Endpoint Leaks the Superad…EPSS 0.22%5.3CVE-2026-23481Blinko path traversal vulnerabilityBlinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an authenticated arbitrary file write vulnerability in saveAdditio…EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2026-23484), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.