CVE-2026-33588

HIGH

Open Notebook < 1.8.3 - Path Traversal via File Upload

Title source: llm
STIX 2.1

Description

Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to create or modify files on the docker container via path traversal.

References (1)

Core 1

Scores

CVSS v3 8.1
EPSS 0.0018
EPSS Percentile 7.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20
Status published
Products (2)
lfnovo/open-notebook < 1.8.4
Open Notebook/Open Notebook < 1.8.3
Published May 07, 2026
Tracked Since May 07, 2026