PT-2026-27215 · Blinkospace · Blinko

Published

2026-03-23

·

Updated

2026-03-23

·

CVE-2026-23487

CVSS v4.0

6.0

Medium

AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an IDOR vulnerability where user.detail Endpoint Leaks the Superadmin Token. This issue has been patched in version 1.8.4.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-23487

Affected Products

Blinko