CVE-2026-33588 Details
Description
Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to create or modify files on the docker container via path traversal.
A path traversal vulnerability has been identified in the file upload feature of Open Notebook version 1.8.3 and prior. This issue arises from inadequate validation of user input in filenames, enabling authenticated users to manipulate upload requests and write files to arbitrary locations within the Docker container's filesystem. The vulnerability could be exploited to overwrite application files or configurations, or to place web shells in directories accessible via the web.
Users can upgrade to Open Notebook version 1.8.4, where this vulnerability has been addressed by sanitizing filenames and validating the resolved path to ensure it remains within the designated upload directory.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/lfnovo/open-notebook/security/advisories/GHSA-x4q2-89g5-594v | ENISA | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-20 | Improper Input Validation | ENISA |
Affected Products
| Product | Versions |
|---|---|
| lfnovo open-notebook | < 1.8.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | ENISA |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 7, 2026 | Initial Analysis | [email protected] |
| May 7, 2026 | New CVE Received | ENISA |