CVE-2026-23882

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the MCP (Model Context Protocol) server creation function allows specifying arbitrary commands and arguments, which are executed when testing the connection. This issue has been patched in version 1.8.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:blinko:blinko:*:*:*:*:*:*:*:*

History

24 Mar 2026, 18:03

Type Values Removed Values Added
CPE cpe:2.3:a:blinko:blinko:*:*:*:*:*:*:*:*
References () https://github.com/blinkospace/blinko/commit/bef6b770743e87c630db2d00d7049dabd96bfe85 - () https://github.com/blinkospace/blinko/commit/bef6b770743e87c630db2d00d7049dabd96bfe85 - Patch
References () https://github.com/blinkospace/blinko/releases/tag/1.8.4 - () https://github.com/blinkospace/blinko/releases/tag/1.8.4 - Release Notes
References () https://github.com/blinkospace/blinko/security/advisories/GHSA-59r2-82p8-c56v - () https://github.com/blinkospace/blinko/security/advisories/GHSA-59r2-82p8-c56v - Vendor Advisory
First Time Blinko
Blinko blinko
Summary
  • (es) Blinko es un proyecto de toma de notas en tarjetas impulsado por IA. Antes de la versión 1.8.4, la función de creación de servidor MCP (Model Context Protocol) permite especificar comandos y argumentos arbitrarios, que se ejecutan al probar la conexión. Este problema ha sido parcheado en la versión 1.8.4.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.2

23 Mar 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-23 21:17

Updated : 2026-03-24 18:03


NVD link : CVE-2026-23882

Mitre link : CVE-2026-23882

CVE.ORG link : CVE-2026-23882


JSON object : View

Products Affected

blinko

  • blinko
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')