CVE-2026-23485

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the filePath parameter accepts path traversal sequences, allowing enumeration of file existence on the server via different error responses. This issue has been patched in version 1.8.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:blinko:blinko:*:*:*:*:*:*:*:*

History

24 Mar 2026, 18:05

Type Values Removed Values Added
References () https://github.com/blinkospace/blinko/commit/9d6fa80a3e11a99886f90e048657443335fd3e7d - () https://github.com/blinkospace/blinko/commit/9d6fa80a3e11a99886f90e048657443335fd3e7d - Patch
References () https://github.com/blinkospace/blinko/releases/tag/1.8.4 - () https://github.com/blinkospace/blinko/releases/tag/1.8.4 - Release Notes
References () https://github.com/blinkospace/blinko/security/advisories/GHSA-5x64-pmfq-pw7q - () https://github.com/blinkospace/blinko/security/advisories/GHSA-5x64-pmfq-pw7q - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CPE cpe:2.3:a:blinko:blinko:*:*:*:*:*:*:*:*
First Time Blinko
Blinko blinko
Summary
  • (es) Blinko es un proyecto de toma de notas en tarjetas impulsado por IA. Antes de la versión 1.8.4, el parámetro filePath acepta secuencias de salto de ruta, permitiendo la enumeración de la existencia de archivos en el servidor a través de diferentes respuestas de error. Este problema ha sido parcheado en la versión 1.8.4.

23 Mar 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-23 21:17

Updated : 2026-03-24 18:05


NVD link : CVE-2026-23485

Mitre link : CVE-2026-23485

CVE.ORG link : CVE-2026-23485


JSON object : View

Products Affected

blinko

  • blinko
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')