Path Traversal Vulnerability in Open Notebook by LF Novo
CVE-2026-33589

8.2HIGH

Key Information:

Vendor
CVE Published:
7 May 2026

What is CVE-2026-33589?

A vulnerability exists in Open Notebook v1.8.3 due to insufficient user input validation in its file upload functionality. This flaw enables attackers to exploit the application, allowing them to access local file contents from the Docker container through a path traversal attack. Such vulnerabilities can lead to exposure of sensitive data and pose significant risks to the application's integrity.

Affected Version(s)

Open Notebook 0 <= 1.8.3

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

CERT-EU
.