In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by jQuery after sanitization, making it dangerous.
oryginał ENCVSS Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HJupyter Notebook
APPJupyter< 5.4.1
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Powiązane podatności
CVE-2021-32798CRITICAL10.0PL ✓ten sam produkt
XSS w Jupyter Notebook umożliwiający RCE przez złośliwy plik ipynb
CVE-2026-42557HIGH8.6ten sam produkt
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Noteb...
CVE-2024-43805HIGH7.6ten sam produkt
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Noteb...
CVE-2024-22421HIGH7.6ten sam produkt
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Noteb...
CVE-2022-24758HIGH7.5ten sam produkt
The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, un...