In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by jQuery after sanitization, making it dangerous.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HJupyter Notebook
APPJupyter< 5.4.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2021-32798CRITICAL10.0PL ✓same product
XSS w Jupyter Notebook umożliwiający RCE przez złośliwy plik ipynb
CVE-2026-42557HIGH8.6same product
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Noteb...
CVE-2024-43805HIGH7.6same product
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Noteb...
CVE-2024-22421HIGH7.6same product
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Noteb...
CVE-2022-24758HIGH7.5same product
The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, un...