CVE-2026-23486

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, a publicly accessible endpoint exposes all user information, including usernames, roles, and account creation dates. This issue has been patched in version 1.8.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:blinko:blinko:*:*:*:*:*:*:*:*

History

24 Mar 2026, 18:04

Type Values Removed Values Added
References () https://github.com/blinkospace/blinko/commit/ec1e3e20384b620b8bf928fe80b4d8546757b419 - () https://github.com/blinkospace/blinko/commit/ec1e3e20384b620b8bf928fe80b4d8546757b419 - Patch
References () https://github.com/blinkospace/blinko/releases/tag/1.8.4 - () https://github.com/blinkospace/blinko/releases/tag/1.8.4 - Release Notes
References () https://github.com/blinkospace/blinko/security/advisories/GHSA-446p-2xf5-frxf - () https://github.com/blinkospace/blinko/security/advisories/GHSA-446p-2xf5-frxf - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CPE cpe:2.3:a:blinko:blinko:*:*:*:*:*:*:*:*
Summary
  • (es) Blinko es un proyecto de toma de notas en tarjetas impulsado por IA. Antes de la versión 1.8.4, un endpoint accesible públicamente expone toda la información del usuario, incluyendo nombres de usuario, roles y fechas de creación de cuentas. Este problema ha sido parcheado en la versión 1.8.4.
First Time Blinko
Blinko blinko

23 Mar 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-23 21:17

Updated : 2026-03-24 18:04


NVD link : CVE-2026-23486

Mitre link : CVE-2026-23486

CVE.ORG link : CVE-2026-23486


JSON object : View

Products Affected

blinko

  • blinko
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor