Report: - Blinko: Authenticated Arbitrary File Write - saveDevPlugin CVE-2026-23484

Report: - Blinko: Authenticated Arbitrary File Write - saveDevPlugin CVE-2026-23484

CVE ID :CVE-2026-23484 Published : March 23, 2026, 9:17 p.m. | 35 minutes ago Description :Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the fileName parameter is not filtered, allowing path traversal to write files anywhere on the file system. Moreover, this interface only requires authProcedure (normal user), not superAdminAuthMiddleware. At time of publication, there are no publicly available patches. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
March 23, 2026
Impact: path traversal