CVE-2026-23483
Blinko: Unauthorized Arbitrary File Read - /plugins
Vexday Risk Score
28Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 6.9EPSS 0.8%KEV nãoPoC —Nuclei simMetasploit —Patch —
Lifecycle
23 Mar 2026Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the plugin file server endpoint uses join() to concatenate paths but does not verify if the final path is within the plugins directory, leading to path traversal. At time of publication, there are no publicly available patches.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
blinkospace · blinkoWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →