VYPR
Unrated severityNVD Advisory· Published Mar 23, 2026· Updated Mar 24, 2026

Blinko: multiple interfaces in the comment feature allow unauthorized access

CVE-2026-23488

Description

Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the /api/v1/comment/create endpoint has an unauthorized access vulnerability, allowing attackers to post comments on any note (including private notes) without authorization, even if the note has not been publicly shared. The /api/v1/comment/list endpoint has the same issue, allowing unauthorized viewing of comments on all notes. This issue has been patched in version 1.8.4.

Affected products

2
  • Blinko/Blinkollm-fuzzy
    Range: <1.8.4.1
  • blinkospace/blinkov5
    Range: < 1.8.4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.