Blinko, an AI-powered card note-taking project, patched two high-severity vulnerabilities in version 1.8.4 after GitHub security advisories disclosed that earlier releases were vulnerable to both arbitrary file read and remote code execution. The first issue, tracked as CVE-2026-23482, affects the /api/file/temp endpoint, which failed to enforce permission checks and did not block path traversal, allowing unauthorized attackers to read arbitrary files from the server. Where scheduled backups were enabled, exposed backup files could reveal all user notes and user tokens.
A second flaw, CVE-2026-23882, allowed OS command injection in Blinko's MCP server creation workflow. In versions before 1.8.4, the connection-testing function accepted arbitrary commands and arguments and executed them, creating an admin-level remote code execution path mapped to CWE-78. The combined disclosures show that unpatched Blinko instances faced risks to confidentiality, integrity, and availability, with fixes released through the project's 1.8.4 update and associated code commits.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
On March 23, 2026, GitHub security advisories disclosed CVE-2026-23882 and CVE-2026-23482 in Blinko. The advisories described risks including admin-level remote command execution and unauthorized reading of server files, including backups that could expose user notes and tokens.
Blinko patched two vulnerabilities affecting versions prior to 1.8.4: an OS command injection in MCP server creation/testing (CVE-2026-23882) and an unauthorized arbitrary file read/path traversal issue in /api/file/temp (CVE-2026-23482). The fixes were referenced through the 1.8.4 release and associated commits.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.