CVE-2026-33587·Docker vulnerability
Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker container via Server-Side Template Injection (SSTI) for user-created transformations.
- Severity
- critical
- Software
- Docker
- Fixed in
- 1.8.4
- Published
- 2026-05-07
Affected versions
Until: 1.8.4
Fixed in: 1.8.4
How to fix this CVE
Update Docker to version 1.8.4 or later to patch the Server-Side Template Injection vulnerability in Open Notebook transformations. This vulnerability allows unauthenticated attackers to inject arbitrary Python code and execute OS commands within Docker containers. Immediately apply the update across all systems running affected versions to prevent remote code execution.
sudo dnf update docker-ce --assumeyesDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST request to Open Notebook transformation endpoints containing template injection payloads such as `{{ __import__('os').system('command') }}` or `{%% for item in ().__class__.__bases__[0].__subclasses__() %%}` in user-created transformation parametersWAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement strict input validation and sanitization on all Open Notebook transformation parameters; block requests containing template syntax characters ({{ }}, {%% %%, etc.) in user input fields; enforce Content Security Policy headers; consider using a WAF rule to detect and block template injection patterns in POST/PUT requests to /transformation endpointsHow to check if you are affected
- Run `docker --version` to check the currently installed Docker version; versions prior to 1.8.4 are vulnerable
- Verify if Open Notebook transformations are enabled by checking Docker container environment variables and mounted configuration files for transformation definitions
- Search Docker logs and container runtime logs for template injection patterns: `docker logs <container_id> | grep -i 'template\|jinja\|{{ }}'`
- Confirm remediation by running `docker --version` again and verifying the version is 1.8.4 or higher, then restart affected containers
FAQ
What is CVE-2026-33587?
CVE-2026-33587 is a critical Server-Side Template Injection (SSTI) vulnerability in Docker's Open Notebook component that allows attackers to execute arbitrary Python and OS commands within containers through improperly sanitized user input in custom transformations.
Is CVE-2026-33587 being actively exploited?
No, this vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and no public exploits are available, however the CVSS 10.0 score indicates high urgency for patching.
What versions of Docker are affected by CVE-2026-33587?
Docker versions prior to 1.8.4 are affected. The vulnerability exists in versions up to and including 1.8.3.
How do I check if my server is vulnerable to CVE-2026-33587?
Run `docker --version` and compare the output against version 1.8.4; if your version is lower, the system is vulnerable. Additionally, check for Open Notebook transformation configurations in your container environment.
Does Defensia detect CVE-2026-33587?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Docker is installed on a monitored server, CVE-2026-33587 will appear in your dashboard with remediation steps.
Related Docker CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2026-33587. Free for 1 server.
Get started free