Unrated severityNVD Advisory· Published Mar 23, 2026· Updated Mar 24, 2026
Blinko: Unauthorized Path Traversal File Enumeration - music-metadata
CVE-2026-23485
Description
Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the filePath parameter accepts path traversal sequences, allowing enumeration of file existence on the server via different error responses. This issue has been patched in version 1.8.4.
Affected products
2- blinkospace/blinkov5Range: < 1.8.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/blinkospace/blinko/commit/9d6fa80a3e11a99886f90e048657443335fd3e7dmitrex_refsource_MISC
- github.com/blinkospace/blinko/releases/tag/1.8.4mitrex_refsource_MISC
- github.com/blinkospace/blinko/security/advisories/GHSA-5x64-pmfq-pw7qmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.