CVE-2026-33587

Severity CVSS v4.0:
CRITICAL
Type:
CWE-20 Input Validation
Publication date:
07/05/2026
Last modified:
07/05/2026

Description

Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker container via Server-Side Template Injection (SSTI) for user-created transformations.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lfnovo:open-notebook:*:*:*:*:*:*:*:* 1.8.4 (excluding)