Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the fileName parameter is not filtered, allowing path traversal to write files anywhere on the file system. Moreover, this interface only requires authProcedure (normal user), not superAdminAuthMiddleware. At time of publication, there are no publicly available patches.
History

Tue, 24 Mar 2026 02:30:00 +0000

Type Values Removed Values Added
Description Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the fileName parameter is not filtered, allowing path traversal to write files anywhere on the file system. Moreover, this interface only requires authProcedure (normal user), not superAdminAuthMiddleware. At time of publication, there are no publicly available patches.
Title Blinko: Authenticated Arbitrary File Write - saveDevPlugin
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-03-23T20:31:19.999Z

Reserved: 2026-01-13T15:47:41.628Z

Link: CVE-2026-23484

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-23T21:17:02.700

Modified: 2026-03-23T21:17:02.700

Link: CVE-2026-23484

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.