Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to create or modify files on the docker container via path traversal.
References
| Link | Resource |
|---|---|
| https://github.com/lfnovo/open-notebook/security/advisories/GHSA-x4q2-89g5-594v | Vendor Advisory |
Configurations
History
07 May 2026, 20:00
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Lfnovo
Lfnovo open-notebook |
|
| CPE | cpe:2.3:a:lfnovo:open-notebook:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.1 |
| CWE | NVD-CWE-noinfo | |
| References | () https://github.com/lfnovo/open-notebook/security/advisories/GHSA-x4q2-89g5-594v - Vendor Advisory |
07 May 2026, 14:51
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-07 11:16
Updated : 2026-05-07 20:00
NVD link : CVE-2026-33588
Mitre link : CVE-2026-33588
CVE.ORG link : CVE-2026-33588
JSON object : View
Products Affected
lfnovo
- open-notebook
CWE
