Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-23882: Arbitrary command execution via Blinko MCP server creation

Blinko, an AI-powered card note-taking project, allowed arbitrary commands and arguments to be specified when creating an MCP (Model Context Protocol) server, which were then executed when the connection was tested. The issue affects versions prior to 1.8.4 and has been patched in that release.

Disclosed 23 March 2026 · Record updated 13 September 2026

Impact

Attackers able to create or configure an MCP server connection could execute arbitrary commands on the host when the connection was tested.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-23882