Executive brief
Blinko is an open-source, self-hosted personal note-taking application designed for privacy. A vulnerability in version 1.8.7 allows authenticated users to view other users' private notes by guessing sequential note identifiers, potentially exposing sensitive content, attachments, and tags without the note owner's consent.
Technical details
The noteReferenceList procedure in Blinko 1.8.7 fails to validate note ownership, allowing authenticated attackers to enumerate and retrieve notes belonging to other users. The vulnerability exists because the endpoint does not verify that the requesting user is the owner of a note before returning its content. An attacker with valid authentication credentials can iterate through sequential note IDs to access private notes from any user on the system, including full content, attachments, and associated tags. This is an insecure direct object reference (IDOR) vulnerability. A fix is available in version 1.8.8 and later.
Affected products
- Blinko Blinko 1.8.7
Timeline
- 2026-09-04: disclosed
- 1.8.8: patched: Fix available in version 1.8.8 and later