GHSA-44mq-cghw-wf5x · Severity: high — An improper input validation, together with an overly permissive default CORS configuration in...
An improper input validation, together with an overly permissive default CORS configuration in Open Notebook v1.8.1 allows remote attacker to trick a legitimate user to alter or delete arbitrary database entries via specially crafted malicious URL. Depending on the deployment, data exfiltration is also possible.
Conclusion & alert: CVE-2026-28201 is rated Moderate Risk (40.9/100): CVSS High severity, with low exploitation likelihood (EPSS 0.06%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-13 | 0.05% | 0.06% | +0.01% |
| 2 | 2026-05-08 | 0.07% | 0.05% | -0.03% |
| 3 | 2026-05-07 | — | 0.07% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.7 | 4.0 | HIGH |
|
— | — | a6d3dc9e-0591-4a13-bce7-0f5b31ff6158 |
| 7.8 | 3.1 | HIGH |
|
1.8 | 5.9 | [email protected] |
GHSA-44mq-cghw-wf5x · Severity: high — An improper input validation, together with an overly permissive default CORS configuration in...
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| lfnovo | open-notebook | < 1.8.3 | cpe:2.3:a:lfnovo:open-notebook:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/lfnovo/open-notebook/security/advisories/GHSA-5wj9-f8q5-8f9c | Vendor Advisory |