open-notebook vulnerability

Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal network services, and localhost-bound services through the application server's direct HTTP requests.

Published 13 Sep 2026Updated 13 Sep 20265 sources
CVSS 8.3

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.