Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to access local files content from the docker container via path traversal.
References
| Link | Resource |
|---|---|
| https://github.com/lfnovo/open-notebook/security/advisories/GHSA-842v-h4cj-r646 | Mitigation Vendor Advisory |
Configurations
History
07 May 2026, 19:49
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Lfnovo
Lfnovo open-notebook |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| CWE | NVD-CWE-noinfo | |
| CPE | cpe:2.3:a:lfnovo:open-notebook:*:*:*:*:*:*:*:* | |
| References | () https://github.com/lfnovo/open-notebook/security/advisories/GHSA-842v-h4cj-r646 - Mitigation, Vendor Advisory |
07 May 2026, 14:51
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-07 11:16
Updated : 2026-05-07 19:49
NVD link : CVE-2026-33589
Mitre link : CVE-2026-33589
CVE.ORG link : CVE-2026-33589
JSON object : View
Products Affected
lfnovo
- open-notebook
CWE
