CVE-2026-33587Disclosure(lfnovo / open-notebook)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker container via Server-Side Template Injection (SSTI) for user-created transformations.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • open-notebook

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-05-12)
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
open-notebook

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-05-07: 2Mentions · 2026-05-12: 3PoC Mentioned / Linked · 2026-05-12: 1Technical Details · 2026-05-07: 2Technical Details · 2026-05-12: 305-0705-12
Signal classification3 categories
Disclosure
360.0%
General
120.0%
PoC
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-072
Disclosure2
2026-05-123
Disclosure1General1PoC1
Full discourse5 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-33587 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on…

    Post summary

    A critical vulnerability (CVE‑2026‑33587) in Open Notebook v1.8.3 allows arbitrary Python/OS command execution through unsanitized user input, with no PoC, patch, or active exploitation reported.

    1000038
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVSS 10 CRITICAL · CVE-2026-33587 · v1.8.3 → 3.1 CVE: CVE-2026-33587 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text reports a critical CVSS score and version details for CVE-2026-33587, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    1000045
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    https://lyrie.ai/research/research/cve-2026-33587-lfnovo-open-notebook #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post announces CVE‑2026‑33587, supplies a proof‑of‑concept for the Lenovo ‘Open Notebook’ flaw, but does not confirm exploitation in the wild or provide a patch.

    0000029
    210 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33587 Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker container via … https://www.cve.org/CVERecord?id=CVE-2026-33587

    Post summary

    The post announces a CVE-2026-33587 vulnerability in Open Notebook v1.8.3, highlighting an input sanitisation flaw that permits code and OS command injection, without providing any PoC or exploitation details.

    0000074
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33587 Server-Side Template Injection in Open Notebook v1.8.3 En... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33587 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet discloses CVE‑2026‑33587 as a server‑side template injection flaw in Open Notebook v1.8.3 and highlights a link for vulnerability details, urging early scans.

    0000041
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applfnovoopen-notebook---

Explore more