CVE-2026-33588: Lfnovo Open-Notebook
High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to create or modify files on the docker container via path traversal.
Affected products
- Lfnovo Open-Notebook: before 1.8.4 (fixed in 1.8.4)
Published 2026-05-07. Last modified 2026-06-17.