VDB
DEBIAN-CVE-2021-32798
DEBIAN-CVE-2021-32798
PUBLISHED
CVSS 9.600000381469727 CRITICAL
The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load. Jupyter Notebook uses a deprecated version of Google Caja to sanitize user inputs. A public Caja bypass can be used to trigger an XSS when a victim opens a malicious ipynb document in Jupyter Notebook. The XSS allows an attacker to execute arbitrary code on the victim computer using Jupyter APIs.
Risk Scores
CVSS v3.1
9.600000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:14 | jupyter-notebook | 0, 0, 0 |
| Debian:11 | jupyter-notebook | 7.0.0-1, 7.0.0-2, 6.4.5-2 |
| Debian:13 | jupyter-notebook | 0, 0, 0 |
| Debian:12 | jupyter-notebook | 0, 0, 0 |
Timeline
- Aug 9, 2021 CVE Published
- Apr 28, 2026 CVE Updated