← back
CVE-2026-23483

Blinko: Unauthorized Arbitrary File Read - /plugins

CVSS 6.9 MEDIUMEPSS 0.8%CWE-22
Vexday Risk Score
28Low
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 6.9EPSS 0.8%KEV nãoPoC Nuclei simMetasploit Patch
Lifecycle
23 Mar 2026Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the plugin file server endpoint uses join() to concatenate paths but does not verify if the final path is within the plugins directory, leading to path traversal. At time of publication, there are no publicly available patches.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
blinkospace · blinko

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →