Skip to content
JupyterGHSA-49qr-xh3w-h436

Jupyter Notebook XSS via untrusted notebooks

Medium6.1CVE-2018-19351 · Published Nov 21, 2018 · updated Sep 27, 2024

Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconvert endpoints can execute JavaScript with access to the server API. In notebook/nbconvert/handlers.py, NbconvertFileHandler and NbconvertPostHandler do not set a Content Security Policy to prevent this.

GitHub advisory

Affected versions

PackageAffectedFixed in
notebook
PyPI
< 5.7.15.7.1
Details and references

More Jupyter advisories

All Jupyter
Advisory
Open redirect in Jupyter Notebook
Low4.4Nov 18, 2020
Cross-site scripting in Jupyter Notebook
Medium5.3Nov 8, 2019
Jupyter Notebook open redirect vulnerability
Medium6.1Apr 9, 2019
Open Redirect vulnerability in jupyterhub and notebook
Medium6.1Apr 2, 2019
Jupyter Notebook XSS via directory name
Medium6.1Nov 21, 2018
Jupyter Notebook file bypasses sanitization, executes JavaScript
High7.8Jul 12, 2018

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.