The number and severity of CVEs published that impact products developed by Lfnovo over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33587CRITICAL Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker container via Server-Side Te | May 7, 2026 | 10.0 | 37 | NO | NO |
CVE-2026-33588HIGH Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to create or modify files on the docker container via path traver | May 7, 2026 | 8.1 | 30 | NO | NO |
CVE-2026-28201HIGH An improper input validation, together with an overly permissive default CORS configuration in Open Notebook v1.8.1 allows remote attacker to trick a legitimate user to alter or de | May 7, 2026 | 7.8 | 29 | NO | NO |
CVE-2026-33589MEDIUM Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to access local files content from the docker container via path | May 7, 2026 | 6.5 | 27 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lfnovo.
Media articles that mention a CVE ID that affects a product developed by Lfnovo — matched by CVE ID, not by vendor name.