Back to search
CVE-2026-33587
Published: May 7, 2026
Modified: May 7, 2026
PUBLISHED
Description
Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker container via Server-Side Template Injection (SSTI) for user-created transformations.
| Vendor | Product | Versions |
|---|---|---|
Open Notebook | Open Notebook | affected 0 - <= 1.8.3 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now