Impact
The Open Notebook application, for releases before 1.11.0, does not validate the URL supplied to the POST /api/sources endpoint. This flaw, classified as CWE-918, allows any authenticated user to instruct the server to perform an HTTP request to an arbitrary address. By choosing internal or cloud‑metadata URLs, an attacker can read sensitive data, probe internal services, or same host as the application, thereby exposing a range of internal resources.
Affected Systems
The vulnerability affects installations of lfnovo open‑notebook that are built with a version less than 1.11.0. Any deployment of that software using an older release, regardless of operating system or hosting environment, is susceptible.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity impact. The EPSS score is available but very low, at <1%, indicating a low probability of exploitation. The absence of URL validation provides a straightforward path for authenticated users to reach internal services. The vulnerability is not currently listed in the CISA KEV catalog, and there are no known public exploits, though its nature makes it attractive for attackers once credentials are obtained.
OpenCVE Enrichment