In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by jQuery after sanitization, making it dangerous.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade jupyter-notebookUpgrade ipython | Nov 9, 2020 | Mar 18, 2018 |
| Freebsd | — | Upgrade py36-notebookUpgrade py34-notebookUpgrade py27-notebookUpgrade py35-notebook | Dec 10, 2025 | Mar 19, 2018 |
| Ubuntu | — | Upgrade ipython3-notebook (Ubuntu Pro)Upgrade ipython3 (Ubuntu Pro)Upgrade ipython-notebook (Ubuntu Pro)Upgrade ipython (Ubuntu Pro)Upgrade ipython3-qtconsole (Ubuntu Pro)Upgrade ipython-notebook-common (Ubuntu Pro) | Mar 22, 2023 | Mar 18, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub