/Vulnerability Library

Blinko < 1.8.4 - Path Traversal

CVE-2026-23482
Verified

Description

Blinko < 1.8.4 contains a path traversal vulnerability caused by lack of permission checks and filtering on the temp/ path in the file server endpoint, letting unauthorized attackers read arbitrary files including backup files with user notes and tokens, exploit requires no special privileges.

Severity

High

CVSS Score

7.5

Exploit Probability

2%

Affected Product

blinko

Published Date

April 27, 2026

Template Author

tx1ee

CVE-2026-23482.yaml
7.5Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2026-23482
CWE ID:
cwe-22

References

https://github.com/blinkospace/blinko/commit/c48851090767feba431418630c495d90a7da1781https://github.com/blinkospace/blinko/security/advisories/GHSA-hrwx-rhrx-f9mmhttps://nvd.nist.gov/vuln/detail/CVE-2026-23482

Remediation Steps

Update to version 1.8.4 or later