CVE-2026-28201

An improper input validation, together with an overly permissive default CORS configuration in Open Notebook v1.8.1 allows remote attacker to trick a legitimate user to alter or delete arbitrary database entries via specially crafted malicious URL. Depending on the deployment, data exfiltration is also possible.
Configurations

Configuration 1 (hide)

cpe:2.3:a:lfnovo:open-notebook:*:*:*:*:*:*:*:*

History

07 May 2026, 20:20

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:lfnovo:open-notebook:*:*:*:*:*:*:*:*
First Time Lfnovo
Lfnovo open-notebook
References () https://github.com/lfnovo/open-notebook/security/advisories/GHSA-5wj9-f8q5-8f9c - () https://github.com/lfnovo/open-notebook/security/advisories/GHSA-5wj9-f8q5-8f9c - Vendor Advisory

07 May 2026, 14:51

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-07 11:16

Updated : 2026-05-07 20:20


NVD link : CVE-2026-28201

Mitre link : CVE-2026-28201

CVE.ORG link : CVE-2026-28201


JSON object : View

Products Affected

lfnovo

  • open-notebook
CWE
CWE-20

Improper Input Validation

CWE-352

Cross-Site Request Forgery (CSRF)

CWE-917

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

NVD-CWE-noinfo