Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal network services, and localhost-bound services through the application server's direct HTTP requests.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal network services, and localhost-bound services through the application server's direct HTTP requests. | |
| Title | Open Notebook before 1.11.0 Server-Side Request Forgery via link-source | |
| First Time appeared |
Lfnovo
Lfnovo open-notebook |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:lfnovo:open-notebook:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lfnovo
Lfnovo open-notebook |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-13T10:45:40.937Z
Reserved: 2026-09-13T10:14:52.461Z
Link: CVE-2026-90769
No data.
Status : Received
Published: 2026-09-13T11:17:01.270
Modified: 2026-09-13T11:17:01.270
Link: CVE-2026-90769
No data.
OpenCVE Enrichment
Updated: 2026-09-13T13:45:17Z
Weaknesses