Impact
The Open Notebook application, prior to version 1.11.0, does not validate the URL supplied to the POST /api/sources endpoint. An authenticated user can supply any URL, causing the server to perform an HTTP request to that address. This allows reading cloud metadata, communicating with internal network services, and accessing localhost‑bound services directly from the application stack, potentially exposing sensitive data and internal resources.
Affected Systems
The vulnerability affects Open Notebook deployments built with lfnovo open‑notebook before version 1.11.0. Any installation of this software using an older release is susceptible, regardless of operating system or environment.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity. With no EPSS score available, the exact exploitation likelihood is unknown, but the lack of URL validation provides a straightforward path for authenticated users to reach internal services. The vulnerability is not currently listed in CISA KEV, but its exploitation could be convenient and destructive, especially in environments where the application has elevated privileges.
OpenCVE Enrichment