Server-Side Template Injection in Open Notebook by LFNovo
CVE-2026-33587
9.2CRITICAL
What is CVE-2026-33587?
The Open Notebook application version 1.8.3 contains a significant vulnerability due to inadequate sanitization of user input. This flaw permits malicious users to execute arbitrary Python code, potentially leading to the execution of operating system commands within the Docker container environment. The vulnerability arises from the Server-Side Template Injection (SSTI) mechanism that processes user-created transformations, underscoring the need for stringent input validation to secure the application against such exploits.
Affected Version(s)
Open Notebook 0 <= 1.8.3
