Server-Side Template Injection in Open Notebook by LFNovo
CVE-2026-33587

9.2CRITICAL

Key Information:

Vendor
CVE Published:
7 May 2026

What is CVE-2026-33587?

The Open Notebook application version 1.8.3 contains a significant vulnerability due to inadequate sanitization of user input. This flaw permits malicious users to execute arbitrary Python code, potentially leading to the execution of operating system commands within the Docker container environment. The vulnerability arises from the Server-Side Template Injection (SSTI) mechanism that processes user-created transformations, underscoring the need for stringent input validation to secure the application against such exploits.

Affected Version(s)

Open Notebook 0 <= 1.8.3

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

CERT-EU
.