Open Notebook
Vendor:
First CVE: May 7, 2026 · Active for under a year
4
Total CVEs
More Total CVEs than 72% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Open Notebook over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 7, 2026
2 months ago
Most Recent CVE
May 7, 2026
80 days ago
CVE Severity & Scoring
Open Notebook4 CVEs
25%
50%
25%
All CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (25.0%)
Network3 (75.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (75.0%)
Unknown0 (0.0%)
Required1 (25.0%)
Privileges Required
Low2 (50.0%)
High0 (0.0%)
None2 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33587CRITICAL Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker container via Server-Side Te | May 7, 2026 | 10.0 | 37 | NO | NO |
CVE-2026-33588HIGH Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to create or modify files on the docker container via path traver | May 7, 2026 | 8.1 | 30 | NO | NO |
CVE-2026-28201HIGH An improper input validation, together with an overly permissive default CORS configuration in Open Notebook v1.8.1 allows remote attacker to trick a legitimate user to alter or de | May 7, 2026 | 7.8 | 29 | NO | NO |
CVE-2026-33589MEDIUM Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to access local files content from the docker container via path | May 7, 2026 | 6.5 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (4 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (4 CVEs).
Media Mentions
Signals from CVEs in this product scope (4 CVEs).
Top CNAs Publishing CVEs For Open Notebook
Top CWEs
Versions
No cataloged versions.