8.1
CVE-2026-33588
- EPSS 0.18%
- Veröffentlicht 07.05.2026 10:28:09
- Zuletzt bearbeitet 07.05.2026 20:00:33
- Quelle a6d3dc9e-0591-4a13-bce7-0f5b31
- CVE-Watchlists
- Unerledigt
Arbitrary File Write Through Path Traversal
Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to create or modify files on the docker container via path traversal.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lfnovo ≫ Open-notebook Version < 1.8.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.079 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
|
| a6d3dc9e-0591-4a13-bce7-0f5b31ff6158 | 7 | 0 | 0 |
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://github.com/lfnovo/open-notebook/security/advisories/GHSA-x4q2-89g5-594v