HIGH
SurrealDB Injection on Open Notebook
Published May 7, 2026
8.7
HIGHCVSS 4.0
EPSS 0.21%
Description
An improper input validation, together with an overly permissive default CORS configuration in Open Notebook v1.8.1 allows remote attacker to trick a legitimate user to alter or delete arbitrary database entries via specially crafted malicious URL. Depending on the deployment, data exfiltration is also possible.
Affected products
-
- Version 0StatusaffectedConstraints<=1.8.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Open Notebook | Open Notebook | unaffected |
|
- < 1.8.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-28345 Advisory
- https://github.com/lfnovo/open-notebook/security/advisories/GHSA-5wj9-f8q5-8f9c vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-28345 | Advisory | |
| https://github.com/lfnovo/open-notebook/security/advisories/GHSA-5wj9-f8q5-8f9c | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ENISA
Published May 7, 2026
Updated May 7, 2026
Reserved Feb 25, 2026
Link CVE-2026-28201
CISA Vulnrichment
Updated May 7, 2026
ENISA EUVD
EUVD-2026-28345 Assigner ENISA
Published May 7, 2026
Updated May 7, 2026
Exploited since n/a
Link EUVD-2026-28345