MIRAGE
Threat IntelligenceCVEs › CVE-2026-23483

CVE-2026-23483 — exposed on the internet

CVE-2026-23483: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in blinkospace blinko

Internet exposure observed by OffSeq scans · last 30 days

1
Exposed hosts
6.9
CVSS
0.8%
EPSS

Found on 1 internet-exposed hosts by OffSeq scans; no in-the-wild exploitation has been observed against OffSeq honeypots in this window.

About CVE-2026-23483

Blinko is an AI-powered card note-taking project. In versions from 1.8.3 and prior, the plugin file server endpoint uses join() to concatenate paths but does not verify if the final path is within the plugins directory, leading to path traversal. At time of publication, there are no publicly available patches.

Vendor: blinkospaceCWE-22

OffSeq internet scanning found CVE-2026-23483 on 1 exposed hosts in the last 30 days. OffSeq honeypots have not recorded in-the-wild exploitation of this CVE in the current window — this page tracks its exposure footprint and status; if exploitation begins, the live honeypot signal will appear here.

Exposed-host countries

Exposed via

http

Open the live CVE-2026-23483 view →

References