Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 13 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal network services, and localhost-bound services through the application server's direct HTTP requests. | |
| Title | Open Notebook before 1.11.0 Server-Side Request Forgery via link-source | |
| First Time appeared |
Lfnovo
Lfnovo open-notebook |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:lfnovo:open-notebook:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lfnovo
Lfnovo open-notebook |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-13T10:45:40.937Z
Reserved: 2026-09-13T10:14:52.461Z
Link: CVE-2026-90769
No data.
Status : Received
Published: 2026-09-13T11:17:01.270
Modified: 2026-09-13T11:17:01.270
Link: CVE-2026-90769
No data.
OpenCVE Enrichment
No data.