CVE-2026-90769
Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal network services, and localhost-bound services through the application server's direct HTTP requests.
Schwachstellenklasse
Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal network services, and localhost-bound services through the application server's direct HTTP requests.
Quellen
- https://github.com/lfnovo/open-notebook
- https://github.com/lfnovo/open-notebook/blob/8889087e317177d7b6e286342ab34e0c9c01d43e/api/routers/sources.py
- https://github.com/lfnovo/open-notebook/commit/9045ea50196927eac7de647bb5b7009349236fb4
- https://github.com/lfnovo/open-notebook/issues/1284
- https://www.vulncheck.com/advisories/open-notebook-before-1.11.0-server-side-request-forgery-via-link-source
- https://github.com/lfnovo/open-notebook/issues/1284
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.