Authenticated Arbitrary File Write Vulnerability in Blinko by BlinkoSpace
CVE-2026-23481
5.3MEDIUM
What is CVE-2026-23481?
Blinko, an AI-powered card note-taking application, has a vulnerability that allows authenticated users to perform arbitrary file writes through the saveAdditionalDevFile function. This can expose the system to potential data manipulation and security breaches. The issue was resolved in version 1.8.4, and users are encouraged to update to this version or later to mitigate the risk.
Affected Version(s)
blinko < 1.8.4
