CVE-2026-33587

Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker conta…

criticalEPSS 0.2 %

Beschreibung

Fehlende Bereinigung von Benutzereingaben in Open Notebook v1.8.3 ermöglicht es dem Anwendungsbenutzer, Python-Code auszuführen (und anschließend Befehle des Betriebssystems) im Docker-Container über Server-Side Template Injection (SSTI) für benutzerdefinierte Transformationen.

Metriken

Severity
critical
kein öffentlicher PoC bekannt
9.2
Quelle: nvd-v4
13.7 %
Erhöht — CVE ist relevanter als mindestens 10 % der heute bewerteten CVEs.
0.2 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-05-07 10:22 UTC
CWE-20

Weakness-Klassen (CWE)

  • CWE-20Class

    Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

    cwe.mitre.org →

Quellen & Referenzen

Verknüpfte Empfehlungen

IDCVE-2026-33587