CVE-2026-23481 identifies an authenticated arbitrary file write vulnerability within the saveAdditionalDevFile function of Blinko, an AI-powered card note-taking project, affecting versions prior to 1.8.4. This flaw carries a CVSS score of 6.5 Medium, indicating a network attack vector with low complexity, requiring low privileges to achieve a high integrity impact. Currently, there is no evidence of active exploitation, nor are public exploit modules available on platforms like Metasploit or ExploitDB, with minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.4CPE matchmatch criteria | cpe:2.3:a:blinko:blinko:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.