Unauthorized Access Vulnerability in Blinko AI Card Note-Taking Software
CVE-2026-23488
6.9MEDIUM
What is CVE-2026-23488?
Blinko, the AI-powered note-taking application, has a vulnerability in its API endpoints that allows unauthorized users to interact with notes without proper authentication. Specifically, the /api/v1/comment/create endpoint permits unauthorized posting of comments on both public and private notes, while the /api/v1/comment/list endpoint grants unrestricted access to view comments on all notes. This exposure compromises user privacy as it enables external attackers to both comment on and access personal notes that should remain confidential. The issue has been addressed in version 1.8.4, which includes security patches to prevent such unauthorized actions.
Affected Version(s)
blinko < 1.8.4
