Vendor
high
advisory
Blinko Authorization Bypass via Insecure Direct Object Reference
1 TTP 1 CVEBlinko version 1.8.7 is vulnerable to an IDOR flaw in multiple tRPC procedures, allowing authenticated users to access, modify, or delete the AI chat history of other users.
Blinko
1t
1c
high
advisory
Blinko Arbitrary File Read Vulnerability (CVE-2026-23482)
2 rules 1 TTPBlinko versions before 1.8.4 are vulnerable to arbitrary file reading due to a lack of permission checks and path traversal filtering on the temp/ path, potentially allowing attackers to read backup files containing sensitive user data.
Blinko
cve-2026-23482
file-read
path-traversal
cloud
2r
1t