CVE Database
/

CVE-2026-23483

Back to search

CVE-2026-23483

Published: Mar 23, 2026

Modified: Mar 24, 2026

PUBLISHED

Description

Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the plugin file server endpoint uses join() to concatenate paths but does not verify if the final path is within the plugins directory, leading to path traversal. At time of publication, there are no publicly available patches.

VendorProductVersions

blinkospace

blinko

affected
<= 1.8.3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2026-23483 - Security Vulnerability | QwikSec