216.73.216.36

CVE-2026-33589

· Published 07/05/2026 11:16 · Modified 07/05/2026 19:49

Labels: CVE-2026-33589 2026-05-07CVE-2026-33589CWE-20NVD-CWE-noinfoa6d3dc9e-0591-4a13-bce7-0f5b31ff6158

Essential information

Published
07/05/2026 11:16
Modified
07/05/2026 19:49
Author
Creator
CVSS
8.2 HIGH (v3) 8.2 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to access local files content from the docker container via path traversal.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
a6d3dc9e-0591-4a13-bce7-0f5b31ff6158
NVD
View on NVD

Affected products (CPE)

ProductCPE
lfnovo / open-notebook cpe:2.3:a:lfnovo:open-notebook:*:*:*:*:*:*:*:*

References