Path Traversal Vulnerability in Blinko by Blinko Space
CVE-2026-23482

8.2HIGH

Key Information:

Status
Vendor
CVE Published:
23 March 2026

What is CVE-2026-23482?

Blinko, an AI-driven note-taking application, has a path traversal vulnerability in its file server endpoint prior to version 1.8.4. This flaw allows unauthorized users to bypass permissible access restrictions, enabling them to read sensitive files stored on the server. Specifically, attackers can exploit this issue to access backup files containing user notes and authentication tokens when backup tasks are enabled. The vulnerability has been addressed in the latest release, version 1.8.4, which implements necessary permission checks to mitigate this risk.

Affected Version(s)

blinko < 1.8.4

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.