CVE-2018-8768

HIGH

Jupyter Notebook < 5.4.1 - Stored Cross-Site Scripting via Malicious Notebook File

Title source: llm
STIX 2.1

Description

In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by jQuery after sanitization, making it dangerous.

References (2)

Core 2
Core References
Mailing List, Third Party Advisory x_refsource_confirm
http://openwall.com/lists/oss-security/2018/03/15/2
Mailing List mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2020/11/msg00033.html

Scores

CVSS v3 7.8
EPSS 0.0110
EPSS Percentile 62.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

Status published
Products (2)
jupyter/notebook < 5.4.1
pypi/notebook 0 - 5.4.1PyPI
Published Mar 18, 2018
Tracked Since Feb 18, 2026