Lack of user input sanitisation in Open Notebook v1.8.3 allows the application user to execute Python code (and subsequently OS commands) on the docker container via Server-Side Template Injection (SSTI) for user-created transformations.CreditsCERT-EUReferenceshttps://github.com/lfnovo/open-notebook/security/advisories/GHSA-f35w-wx37-26q7