Path Traversal Vulnerability in Open Notebook by LF Novo
CVE-2026-33588
7HIGH
What is CVE-2026-33588?
The Open Notebook application version 1.8.3 suffers from a path traversal vulnerability due to insufficient user input validation in its file upload functionality. This flaw allows users to manipulate file paths, which could lead to unauthorized file creation or modification within the Docker container environment. As a result, an attacker could exploit this vulnerability to gain access to sensitive data or perform unauthorized operations on the system.
Affected Version(s)
Open Notebook 0 <= 1.8.3
