CVE-2026-85607 Overview
CVE-2026-85607 is an Insecure Direct Object Reference (IDOR) vulnerability in Blinko 1.8.7, an open-source AI note and conversation platform. The flaw affects multiple authenticated tRPC procedures in server/routerTrpc/message.ts (message.list, message.update, message.delete, message.clearAfter) and server/routerTrpc/conversation.ts (conversation.clearMessages). These procedures query the database using caller-supplied conversation or message IDs without validating resource ownership. Any authenticated user can enumerate sequential integer IDs to read, modify, or delete other users' AI chat histories. The issue is tracked under CWE-639: Authorization Bypass Through User-Controlled Key.
Critical Impact
Authenticated attackers can read, alter, and destroy any other user's full AI conversation history by iterating integer IDs against the affected tRPC endpoints.
Affected Products
- Blinko 1.8.7 (server/routerTrpc/message.ts)
- Blinko 1.8.7 (server/routerTrpc/conversation.ts)
- Fixed in Blinko 1.8.8
Discovery Timeline
- 2026-09-04 - CVE-2026-85607 published to the National Vulnerability Database
- 2026-09-10 - Last updated in NVD database
Technical Details for CVE-2026-85607
Vulnerability Analysis
Blinko exposes chat and conversation management operations through tRPC procedures that gate access with an authentication check but omit an ownership check. When a client invokes message.list, the handler retrieves messages by the supplied conversationId and returns them regardless of which account created that conversation. The same pattern repeats across message.update, message.delete, message.clearAfter, and conversation.clearMessages.
Because Blinko assigns conversations and messages sequential integer identifiers, an attacker can simply enumerate IDs starting from 1. This yields full read access to other users' AI prompts and model responses, which frequently contain personal, business, or credential-adjacent data. Write access enables tampering with prior messages or wiping conversations entirely, producing an integrity and availability impact on top of the confidentiality breach. See the VulnCheck Blinko Advisory for the disclosure record.
Root Cause
The root cause is missing authorization on object references. Each affected procedure trusts the conversationId or message id supplied by the caller and issues a database query without joining or filtering on the authenticated user's account ID. Authentication is verified, but authorization to the specific resource is not.
Attack Vector
Exploitation requires only a valid Blinko account and network access to the application. An attacker authenticates normally, then issues tRPC requests substituting arbitrary integer IDs for conversationId or message id. No user interaction from the victim is needed. The affected source files can be reviewed in the GitHub Blinko Message Code and GitHub Blinko Conversation Code.
// No verified public exploit code is available.
// Conceptually, an authenticated attacker calls:
// trpc.message.list({ conversationId: <victim_id> })
// trpc.message.update({ id: <victim_msg_id>, content: "..." })
// trpc.conversation.clearMessages({ conversationId: <victim_id> })
// The server returns or mutates data without checking ownership.
Detection Methods for CVE-2026-85607
Indicators of Compromise
- Sequential enumeration of conversationId or message id values from a single authenticated session in tRPC access logs.
- Requests to message.list, message.update, message.delete, message.clearAfter, or conversation.clearMessages where the target resource does not belong to the authenticated user.
- Unexpected mass deletion or truncation of AI conversation records in the Blinko database.
Detection Strategies
- Correlate authenticated user IDs against the owner of the requested conversationId in application logs and alert on mismatches.
- Baseline normal per-user request rates against the affected tRPC procedures and flag statistical outliers indicating enumeration.
- Deploy Web Application Firewall (WAF) rules that inspect tRPC POST bodies for rapid ID iteration patterns.
Monitoring Recommendations
- Ingest Blinko application logs into a centralized logging platform and retain full request bodies for the affected procedures.
- Monitor database audit logs for bulk DELETE or UPDATE operations against message and conversation tables outside expected user contexts.
- Alert on any single account issuing high-volume calls to conversation.clearMessages or message.clearAfter.
How to Mitigate CVE-2026-85607
Immediate Actions Required
- Upgrade Blinko to version 1.8.8 or later, which addresses the missing authorization checks in the affected tRPC routers.
- Audit database records for unauthorized reads, modifications, or deletions of messages and conversations since deployment of 1.8.7.
- Rotate credentials and secrets that users may have shared in AI conversations exposed by this issue.
Patch Information
The fix is available in the Blinko 1.8.8 release. Review the corrected router implementations in the GitHub Blinko Message Code and GitHub Blinko Conversation Code. Additional context is available in GitHub Blinko Issue #1218 and the main GitHub Blinko Repository.
Workarounds
- Restrict Blinko to trusted users only, since any authenticated account can exploit the flaw against every other account.
- Place Blinko behind an authenticated reverse proxy that enforces per-user rate limiting on tRPC endpoints to slow enumeration.
- If upgrading immediately is not possible, apply a local patch to each affected procedure that filters queries by accountId = ctx.session.userId.
# Example: verify the running Blinko version and upgrade via container image
docker inspect blinko --format '{{.Config.Image}}'
docker pull blinkospace/blinko:1.8.8
docker stop blinko && docker rm blinko
docker run -d --name blinko blinkospace/blinko:1.8.8
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.