THREAT OPS › Threat News › [NVD] CVE-2026-90769 (HIGH 7.7) — Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal network services, and localhost-b
[NVD] CVE-2026-90769 (HIGH 7.7) — Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal network services, and localhost-b
CVE-2026-90769 CVSS: 7.7 HIGH Published: 2026-09-13T11:17:01.270
Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal network services, and localhost-bound services through the application server's direct
Indicators of compromise
- CVE-2026-90769cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-90769