CVE-2026-33587
EUVD-2026-2834607.05.2026, 11:16
Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker container via Server-Side Template Injection (SSTI) for user-created transformations.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| lfnovo | open-notebook | 𝑥 < 1.8.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration