CVE-2026-23882 PUBLISHED

Blinko: Admin RCE - MCP Server Command Injection

Assigner: GitHub_M
Reserved: 16.01.2026 Published: 23.03.2026 Updated: 23.03.2026

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the MCP (Model Context Protocol) server creation function allows specifying arbitrary commands and arguments, which are executed when testing the connection. This issue has been patched in version 1.8.4.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor blinkospace
Product blinko
Versions
  • Version < 1.8.4 is affected

References

Problem Types

  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE