Vulnerabilidad · Publicado 13/09/2026
Open Notebook versiones anteriores a 1.11.0 contiene una falla de validación en el parámetro URL del endpoint POST /api/sources que permite a usuarios autenticados ejecutar solicitudes HTTP arbitrarias desde el servidor hacia servicios internos, metadatos en la nube y servicios locales. Esto expone credenciales de infraestructura en cloud (AWS, Azure, GCP) y datos sensibles de redes corporativas internas en organizaciones LATAM que utilizan esta plataforma.
Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal network services, and localhost-bound services through the application server's direct HTTP requests.
Score: 7.7/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CWE-918
Publicado en NIST NVD.