Path Traversal Vulnerability in Blinko AI-Powered Card Note-Taking Product
CVE-2026-23483

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
23 March 2026

What is CVE-2026-23483?

The Blinko plugin, an AI-powered card note-taking solution, is susceptible to a path traversal vulnerability due to improper path validation in its file server endpoint. In versions 1.8.3 and earlier, the application uses the join() method to concatenate file paths without ensuring that the resulting path stays within the confines of the plugins directory. This oversight can enable malicious actors to exploit the vulnerability to access unauthorized files on the server. At the time of publishing this information, there are no patches available to address this security flaw.

Affected Version(s)

blinko <= 1.8.3

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.