Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, there is an IDOR vulnerability where user.detail Endpoint Leaks the Superadmin Token. This issue has been patched in version 1.8.4.
References
Configurations
History
No history.
Information
Published : 2026-03-23 21:17
Updated : 2026-03-24 18:04
NVD link : CVE-2026-23487
Mitre link : CVE-2026-23487
CVE.ORG link : CVE-2026-23487
JSON object : View
Products Affected
blinko
- blinko
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
