Blinko < 1.8.4 contains a path traversal vulnerability caused by lack of permission checks and filtering on the temp/ path in the file server endpoint, letting unauthorized attackers read arbitrary files including backup files with user notes and tokens, exploit requires no special privileges.
id: CVE-2026-23482
info:
name: Blinko < 1.8.4 - Path Traversal
author: tx1ee
severity: high
...