8.2
CVE-2026-33589
- EPSS 0.18%
- Veröffentlicht 07.05.2026 10:31:52
- Zuletzt bearbeitet 07.05.2026 19:49:40
- Quelle a6d3dc9e-0591-4a13-bce7-0f5b31
- CVE-Watchlists
- Unerledigt
Arbitrary File Read via Local File Inclusion (LFI)
Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to access local files content from the docker container via path traversal.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lfnovo ≫ Open-notebook Version < 1.8.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.077 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| a6d3dc9e-0591-4a13-bce7-0f5b31ff6158 | 8.2 | 0 | 0 |
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://github.com/lfnovo/open-notebook/security/advisories/GHSA-842v-h4cj-r646