VYPR

NewNotebook API

by Velocidex

CVEs (1)

  • CVE-2026-18640HigAug 11, 2026
    risk 0.46cvss 7.1epss

    The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook record outside the org's data store directory. The file written must have an extension of ".json.db" but can otherwise overwrite…