7
/ 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Description
Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to create or modify files on the docker container via path traversal.
Basic Information
ID
CVE-2026-33588
Source
ENISA
Published
May 7, 2026 at 10:28
Affected Product
Vendor
Open Notebook
Product
Open Notebook
Affected Versions
Open Notebook Open Notebook 0