CyberRota Analysis
AI-GeneratedOpen Notebook versions prior to 1.11.0 are vulnerable due to inadequate validation of the URL parameter in the POST /api/sources endpoint, enabling authenticated users to execute server-side requests to internal services. This flaw allows attackers to access sensitive information from cloud metadata and internal network services, posing a significant risk to data confidentiality and integrity. Organizations using Open Notebook should prioritize patching this vulnerability to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal network services, and localhost-bound services through the application server's direct HTTP requests.