CVE-2018-8768 PUBLISHED

In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by jQuery after sanitization, making it dangerous.

EPSS 0.12% · 30.9th percentile

Risk Scores

EPSS Score
0.12%
30.9th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSipython0, 2.3.0-2ubuntu1, 2.3.0-2ubuntu2

Timeline

References

Open in Interactive Console →