IDOR Vulnerability in Blinko Card Note-Taking Application by Blinko Space
CVE-2026-23487
6MEDIUM
What is CVE-2026-23487?
Blinko, an AI-powered card note-taking application, contains an IDOR vulnerability in its user.detail endpoint that prior to version 1.8.4 could leak sensitive superadmin tokens. This security flaw has been addressed and patched in the latest version, ensuring enhanced protection for users. Developers and administrators are encouraged to update to version 1.8.4 or later to safeguard against potential exploitation.
Affected Version(s)
blinko < 1.8.4
