Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal network services, and localhost-bound services through the application server's direct HTTP requests.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal network services, and localhost-bound services through the application server's direct HTTP requests. | |
| Title | Open Notebook before 1.11.0 Server-Side Request Forgery via link-source | |
| First Time appeared |
Lfnovo
Lfnovo open-notebook |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:lfnovo:open-notebook:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lfnovo
Lfnovo open-notebook |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T15:36:18.070Z
Reserved: 2026-09-13T10:14:52.461Z
Link: CVE-2026-90769
No data.
Status : Received
Published: 2026-09-13T11:17:01.270
Modified: 2026-09-14T16:17:38.833
Link: CVE-2026-90769
No data.
OpenCVE Enrichment
Updated: 2026-09-14T14:00:05Z
Weaknesses