Unauthorized Access Vulnerability in Blinko AI Card Note-Taking Software
CVE-2026-23488

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
23 March 2026

What is CVE-2026-23488?

Blinko, the AI-powered note-taking application, has a vulnerability in its API endpoints that allows unauthorized users to interact with notes without proper authentication. Specifically, the /api/v1/comment/create endpoint permits unauthorized posting of comments on both public and private notes, while the /api/v1/comment/list endpoint grants unrestricted access to view comments on all notes. This exposure compromises user privacy as it enables external attackers to both comment on and access personal notes that should remain confidential. The issue has been addressed in version 1.8.4, which includes security patches to prevent such unauthorized actions.

Affected Version(s)

blinko < 1.8.4

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.