Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an authenticated arbitrary file write vulnerability in saveAdditionalDevFile. This issue has been patched in version 1.8.4.
References
Configurations
History
No history.
Information
Published : 2026-03-23 21:17
Updated : 2026-03-24 18:50
NVD link : CVE-2026-23481
Mitre link : CVE-2026-23481
CVE.ORG link : CVE-2026-23481
JSON object : View
Products Affected
blinko
- blinko
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
