PT-2026-27213 · Blinko · Blinko

Tx1Ee

·

Published

2026-03-23

·

Updated

2026-03-23

·

CVE-2026-23485

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Blinko versions prior to 1.8.4
Description Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the filePath parameter accepts path traversal sequences. This allows for the enumeration of file existence on the server through differing error responses.
Recommendations Update to version 1.8.4 or later.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-23485
GHSA-5X64-PMFQ-PW7Q

Affected Products

Blinko