---
id: CVE-2026-85624
title: >-
  Blinko 1.8.7 contains a cross-user private note disclosure vulnerability in
  the noteReferenceList procedure that performs no ownership verification on
  supplied note identifiers
summary: >-
  Blinko 1.8.7 contains a cross-user private note disclosure vulnerability in
  the noteReferenceList procedure that performs no ownership verification on
  supplied note identifiers. Authenticated attackers can enumerate sequential
  note IDs a…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-639
published: '2026-09-04'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:53:23.707'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85624'
references:
  - url: 'https://github.com/blinkospace/blinko'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/blinkospace/blinko/blob/1.8.8/server/routerTrpc/note.ts'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/blinkospace/blinko/issues/1217'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/blinko-1.8.7-cross-user-private-note-disclosure-via-notereferencelist
    label: disclosure@vulncheck.com
  - url: 'https://github.com/blinkospace/blinko/issues/1217'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00422
epssPercentile: 0.33816
ingestedAt: '2026-09-10T16:57:28.704Z'
---

## Overview

Blinko 1.8.7 contains a cross-user private note disclosure vulnerability in the noteReferenceList procedure that performs no ownership verification on supplied note identifiers. Authenticated attackers can enumerate sequential note IDs and retrieve complete content of other users' private notes including attachments and tags.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
