{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/blinko-1.8.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:blinko:blinko:1.8.7:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-85607"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Blinko (1.8.7)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Blinko"],"content_html":"\u003cp\u003eBlinko version 1.8.7 contains an Insecure Direct Object Reference (IDOR) vulnerability within multiple tRPC procedures located in 'server/routerTrpc/message.ts' and 'server/routerTrpc/conversation.ts'. The affected procedures include message.list, message.update, message.delete, message.clearAfter, and conversation.clearMessages. While the application requires authentication to access these functions, the server fails to perform authorization checks to ensure the requested resource belongs to the authenticated user. By providing an arbitrary, enumerated conversation or message ID, an attacker can access the private AI chat history of any user on the system. This vulnerability enables unauthorized data exfiltration, the manipulation of sensitive conversation content, and the permanent destruction of user data through message or conversation deletion. Defenders should prioritize patching this vulnerability due to the potential for large-scale data compromise in multi-user Blinko environments.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows any authenticated user to read, modify, or delete the private AI chat history of other users. In a multi-user deployment, this leads to unauthorized information disclosure and loss of data integrity, with the risk of clearing entire chat databases through sequential ID enumeration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize upgrading Blinko to the latest secure version addressing CVE-2026-85607. Monitor application-level logs for high-frequency tRPC request patterns where a single authenticated user session requests or deletes an abnormally high number of distinct conversation or message IDs within a short timeframe.\u003c/p\u003e\n","date_modified":"2026-09-04T15:27:41Z","date_published":"2026-09-04T15:27:41Z","id":"https://feed.craftedsignal.io/briefs/2026-09-blinko-idor/","summary":"Blinko version 1.8.7 is vulnerable to an IDOR flaw in multiple tRPC procedures, allowing authenticated users to access, modify, or delete the AI chat history of other users.","title":"Blinko Authorization Bypass via Insecure Direct Object Reference","url":"https://feed.craftedsignal.io/briefs/2026-09-blinko-idor/"}],"language":"en","title":"CraftedSignal Threat Feed - Blinko (1.8.7)","version":"https://jsonfeed.org/version/1.1"}