CVE-2026-23488 is an unauthorized access vulnerability affecting Blinko AI-powered card note-taking projects prior to version 1.8.4. This flaw allows unauthenticated attackers to post and view comments on any note, including private ones, via the /api/v1/comment/create and /api/v1/comment/list endpoints. Rated with a CVSS score of 5.3 (Medium), it has a network attack vector with low complexity, requiring no privileges or user interaction, leading to unauthorized viewing and posting of comments on private notes. There is currently no evidence of active exploitation, nor is public exploit code or significant community discussion available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.4CPE matchmatch criteria | cpe:2.3:a:blinko:blinko:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.