Data Exposure Vulnerability in Blinko by Blinko Space
CVE-2026-23486
6.9MEDIUM
What is CVE-2026-23486?
Blinko, an AI-driven card note-taking application, has a security vulnerability that allows unauthorized access to sensitive user information. Before version 1.8.4, this application featured a publicly accessible endpoint that exposed critical data such as usernames, user roles, and account creation timestamps. The exposure of such information could lead to various security risks including identity theft and unauthorized account access. This vulnerability has been addressed in version 1.8.4, which includes updates to secure all user data.
Affected Version(s)
blinko < 1.8.4
