VDB

DEBIAN-CVE-2021-32798

DEBIAN-CVE-2021-32798 PUBLISHED CVSS 9.600000381469727 CRITICAL

The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load. Jupyter Notebook uses a deprecated version of Google Caja to sanitize user inputs. A public Caja bypass can be used to trigger an XSS when a victim opens a malicious ipynb document in Jupyter Notebook. The XSS allows an attacker to execute arbitrary code on the victim computer using Jupyter APIs.

Risk Scores

CVSS v3.1
9.600000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:14jupyter-notebook0, 0, 0
Debian:11jupyter-notebook7.0.0-1, 7.0.0-2, 6.4.5-2
Debian:13jupyter-notebook0, 0, 0
Debian:12jupyter-notebook0, 0, 0

Timeline

  • Aug 9, 2021 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›