The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load. Jupyter Notebook uses a deprecated version of Google Caja to sanitize user inputs. A public Caja bypass can be used to trigger an XSS when a victim opens a malicious ipynb document in Jupyter Notebook. The XSS allows an attacker to execute arbitrary code on the victim computer using Jupyter APIs.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "6.4.8-1", "binary_name": "jupyter-notebook" }, { "binary_version": "6.4.8-1", "binary_name": "python-notebook-doc" }, { "binary_version": "6.4.8-1", "binary_name": "python3-notebook" } ] }