CVE-2026-23483 PUBLISHED

Blinko: Unauthorized Arbitrary File Read - /plugins

Assigner: GitHub_M
Reserved: 13.01.2026 Published: 23.03.2026 Updated: 23.03.2026

Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the plugin file server endpoint uses join() to concatenate paths but does not verify if the final path is within the plugins directory, leading to path traversal. At time of publication, there are no publicly available patches.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor blinkospace
Product blinko
Versions
  • Version <= 1.8.3 is affected

References

Problem Types

  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE