216.73.217.22

CVE-2026-28201

· Published 07/05/2026 11:16 · Modified 07/05/2026 20:20

Labels: CVE-2026-28201 2026-05-07CVE-2026-28201CWE-20NVD-CWE-noinfoa6d3dc9e-0591-4a13-bce7-0f5b31ff6158

Essential information

Published
07/05/2026 11:16
Modified
07/05/2026 20:20
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An improper input validation, together with an overly permissive default CORS configuration in Open Notebook v1.8.1 allows remote attacker to trick a legitimate user to alter or delete arbitrary database entries via specially crafted malicious URL. Depending on the deployment, data exfiltration is also possible.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
a6d3dc9e-0591-4a13-bce7-0f5b31ff6158
NVD
View on NVD

Affected products (CPE)

ProductCPE
lfnovo / open-notebook cpe:2.3:a:lfnovo:open-notebook:*:*:*:*:*:*:*:*

References