JupyterGHSA-6cwv-x26c-w2q4
Jupyter Notebook file bypasses sanitization, executes JavaScript
High7.8CVE-2018-8768 · Published Jul 12, 2018 · updated Dec 7, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| notebook PyPI | < 5.4.1 | 5.4.1 |
Details and references
In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by jQuery after sanitization, making it dangerous.
- CVSS 3.0
- CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Also known as
- CVE-2018-8768, PYSEC-2018-57
More Jupyter advisories
All Jupyter| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Nov 212018 | Jupyter Notebook XSS via untrusted notebooks CVE-2018-19351Medium6.1fixed in 5.7.1 | Medium6.1 | 5.7.1 |
| Nov 212018 | Jupyter Notebook XSS via directory name CVE-2018-19352Medium6.1fixed in 5.7.2 | Medium6.1 | 5.7.2 |
| Apr 22019 | Open Redirect vulnerability in jupyterhub and notebook CVE-2019-10255Medium6.1fixed in 0.9.6, 5.7.8 | Medium6.1 | 0.9.6, 5.7.8 |
| Apr 92019 | Jupyter Notebook open redirect vulnerability CVE-2019-10856Medium6.1fixed in 5.7.8 | Medium6.1 | 5.7.8 |
| Nov 82019 | Cross-site scripting in Jupyter Notebook CVE-2018-21030Medium5.3fixed in 5.5.0rc1 | Medium5.3 | 5.5.0rc1 |
| Nov 182020 | Open redirect in Jupyter Notebook CVE-2020-26215Low4.4fixed in 6.1.5 | Low4.4 | 6.1.5 |