CVE-2026-23483
Blinko: Unauthorized Arbitrary File Read - /plugins
Vexday Risk Score
28Bajo
Decisión SSVC (CISA)
Attend
PoC disponible → seguir de cerca
CVSS 6.9EPSS 0.8%KEV nãoPoC —Nuclei simMetasploit —Patch —
Ciclo de vida
23 mar 2026Publicada en NVD
Recomendación: Planificar corrección próxima — ya existe PoC pública.
Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the plugin file server endpoint uses join() to concatenate paths but does not verify if the final path is within the plugins directory, leading to path traversal. At time of publication, there are no publicly available patches.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Productos afectados
blinkospace · blinko¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →