CVE-2026-23882: Arbitrary command execution via Blinko MCP server creation
Blinko, an AI-powered card note-taking project, allowed arbitrary commands and arguments to be specified when creating an MCP (Model Context Protocol) server, which were then executed when the connection was tested. The issue affects versions prior to 1.8.4 and has been patched in that release.
Disclosed 23 March 2026 · Record updated 13 September 2026
Impact
Attackers able to create or configure an MCP server connection could execute arbitrary commands on the host when the connection was tested.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-23882
