CVE-2026-28201
EUVD-2026-2834507.05.2026, 11:16
An improper input validation, together with an overly permissive default CORS configuration in Open Notebook v1.8.1 allows remote attacker to trick a legitimate user to alter or delete arbitrary database entries via specially crafted malicious URL. Depending on the deployment, data exfiltration is also possible.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| lfnovo | open-notebook | 𝑥 < 1.8.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration