CVE-2026-33589
Analyzed
Analyzed - Analysis Complete
Path Traversal in Open Notebook File Upload
Publication date: 2026-05-07
Last updated on: 2026-05-07
Assigner: ENISA
Description
Description
Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to access local files content from the docker container via path traversal.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| lfnovo | open-notebook | to 1.8.4 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-20 | The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly. |