Skip to content
JupyterGHSA-jqwc-jm56-wcwj

Cross-site scripting in Jupyter Notebook

Medium5.3CVE-2018-21030 · Published Nov 8, 2019 · updated Oct 7, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
notebook
PyPI
< 5.5.0rc15.5.0rc1
Details and references

Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-79
Also known as
CVE-2018-21030, PYSEC-2019-157

More Jupyter advisories

All Jupyter
DateAdvisory
Apr 92019Jupyter Notebook open redirect vulnerability
CVE-2019-10856Medium6.1fixed in 5.7.8
Apr 22019Open Redirect vulnerability in jupyterhub and notebook
CVE-2019-10255Medium6.1fixed in 0.9.6, 5.7.8
Nov 212018Jupyter Notebook XSS via directory name
CVE-2018-19352Medium6.1fixed in 5.7.2
Nov 212018Jupyter Notebook XSS via untrusted notebooks
CVE-2018-19351Medium6.1fixed in 5.7.1
Nov 182020Open redirect in Jupyter Notebook
CVE-2020-26215Low4.4fixed in 6.1.5
Nov 242020Open redirect in Jupyter Server
CVE-2020-26232Medium4.1fixed in 1.0.6

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.