The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook record outside the org's data store directory. The file written must have an extension of ".json.db" but can otherwise overwrite other metadata files (such as ACL records, hunts etc). This can corrupt these files and cause data corruption.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook record outside the org's data store directory. The file written must have an extension of ".json.db" but can otherwise overwrite other metadata files (such as ACL records, hunts etc). This can corrupt these files and cause data corruption. | |
| Title | Velociraptor directory traversal via the NewNotebook API | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2026-08-11T17:33:21.340Z
Reserved: 2026-08-03T10:46:49.793Z
Link: CVE-2026-18640
Updated: 2026-08-11T17:33:18.691Z
Status : Received
Published: 2026-08-11T16:17:30.713
Modified: 2026-08-11T18:17:21.760
Link: CVE-2026-18640
No data.
OpenCVE Enrichment
No data.