← Zuruck zu CVEs
CVE-2026-23483
MEDIUM5.3
Beschreibung
Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the plugin file server endpoint uses join() to concatenate paths but does not verify if the final path is within the plugins directory, leading to path traversal. At time of publication, there are no publicly available patches.
CVE Details
CVSS v3.1 Bewertung5.3
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht3/23/2026
Zuletzt geandert3/24/2026
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
blinko:blinko
Schwachen (CWE)
CWE-22
Referenzen
https://github.com/blinkospace/blinko/security/advisories/GHSA-54c7-9gxh-fg9v(security-advisories@github.com)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.