VYPR
Medium severity6.5NVD Advisory· Published May 7, 2026· Updated May 7, 2026

CVE-2026-33589

CVE-2026-33589

Description

Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to access local files content from the docker container via path traversal.

Affected products

2
  • Lfnovo/Open Notebookinferred2 versions
    = 1.8.3+ 1 more
    • (no CPE)range: = 1.8.3
    • cpe:2.3:a:lfnovo:open-notebook:*:*:*:*:*:*:*:*range: <1.8.4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.