CVE-2026-33589

MEDIUM

Open Notebook File Upload - Path Traversal Arbitrary File Read

Title source: manual
STIX 2.1

Description

Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to access local files content from the docker container via path traversal.

References (1)

Core 1

Scores

CVSS v3 6.5
EPSS 0.0018
EPSS Percentile 7.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (2)
lfnovo/open-notebook < 1.8.4
Open Notebook/Open Notebook < 1.8.3
Published May 07, 2026
Tracked Since May 07, 2026