Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, a publicly accessible endpoint exposes all user information, including usernames, roles, and account creation dates. This issue has been patched in version 1.8.4.
References
Configurations
History
No history.
Information
Published : 2026-03-23 21:17
Updated : 2026-03-24 18:04
NVD link : CVE-2026-23486
Mitre link : CVE-2026-23486
CVE.ORG link : CVE-2026-23486
JSON object : View
Products Affected
blinko
- blinko
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
