CVE-2026-23483

Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the plugin file server endpoint uses join() to concatenate paths but does not verify if the final path is within the plugins directory, leading to path traversal. At time of publication, there are no publicly available patches.
Configurations

Configuration 1 (hide)

cpe:2.3:a:blinko:blinko:*:*:*:*:*:*:*:*

History

24 Mar 2026, 18:46

Type Values Removed Values Added
Summary
  • (es) Blinko es un proyecto de toma de notas en tarjetas impulsado por IA. En las versiones 1.8.3 y anteriores, el endpoint del servidor de archivos del plugin utiliza join() para concatenar rutas pero no verifica si la ruta final está dentro del directorio de plugins, lo que lleva a un salto de ruta. En el momento de la publicación, no hay parches disponibles públicamente.
CPE cpe:2.3:a:blinko:blinko:*:*:*:*:*:*:*:*
References () https://github.com/blinkospace/blinko/security/advisories/GHSA-54c7-9gxh-fg9v - () https://github.com/blinkospace/blinko/security/advisories/GHSA-54c7-9gxh-fg9v - Vendor Advisory
First Time Blinko
Blinko blinko
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

23 Mar 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-23 21:17

Updated : 2026-03-24 18:46


NVD link : CVE-2026-23483

Mitre link : CVE-2026-23483

CVE.ORG link : CVE-2026-23483


JSON object : View

Products Affected

blinko

  • blinko
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')