CVE-2026-23484

MEDIUM

blinko <= 1.8.3 - Authenticated Path Traversal and Arbitrary File Write via fileName Parameter

Title source: llm
STIX 2.1

Description

Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the fileName parameter is not filtered, allowing path traversal to write files anywhere on the file system. Moreover, this interface only requires authProcedure (normal user), not superAdminAuthMiddleware. At time of publication, there are no publicly available patches.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0034
EPSS Percentile 25.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
blinko/blinko < 1.8.3
blinkospace/blinko <= 1.8.3
Published Mar 23, 2026
Tracked Since Mar 24, 2026