VYPR

blinkospace/blinko

by GitHub

CVEs (2)

  • CVE-2026-23484MedMar 23, 2026
    risk 0.42cvss 6.5epss 0.00

    Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the fileName parameter is not filtered, allowing path traversal to write files anywhere on the file system. Moreover, this interface only requires authProcedure (normal user), not…

  • CVE-2026-23483MedMar 23, 2026
    risk 0.35cvss 5.3epss 0.01

    Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the plugin file server endpoint uses join() to concatenate paths but does not verify if the final path is within the plugins directory, leading to path traversal. At time of publication, there…