PT-2026-27214 · Blinkospace · Blinko

Published

2026-03-23

·

Updated

2026-03-23

·

CVE-2026-23486

CVSS v4.0

6.9

Medium

AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, a publicly accessible endpoint exposes all user information, including usernames, roles, and account creation dates. This issue has been patched in version 1.8.4.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2026-23486

Affected Products

Blinko