CVE-2026-33587
Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker conta…
criticalEPSS 0.2 %
Beschreibung
Fehlende Bereinigung von Benutzereingaben in Open Notebook v1.8.3 ermöglicht es dem Anwendungsbenutzer, Python-Code auszuführen (und anschließend Befehle des Betriebssystems) im Docker-Container über Server-Side Template Injection (SSTI) für benutzerdefinierte Transformationen.
Metriken
Severity
critical
80.85
kein öffentlicher PoC bekannt
9.2
Veröffentlicht
2026-05-07 10:22 UTC
CWE-20
Weakness-Klassen (CWE)
CWE-20Class
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
cwe.mitre.org →
Quellen & Referenzen
Verknüpfte Empfehlungen
IDCVE-2026-33587