CVE-2026-33587 - Remote Code Execution (RCE) via Server-Side Template Injection (SSTI)
CVE ID :CVE-2026-33587
Published : May 7, 2026, 11:16 a.m. | 1 hour, 1 minute ago
Description :Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker container via Server-Side Template Injection (SSTI) for user-created transformations.
Severity: 9.2 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : May 7, 2026, 11:16 a.m. | 1 hour, 1 minute ago
Description :Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker container via Server-Side Template Injection (SSTI) for user-created transformations.
Severity: 9.2 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...