Untrusted notebook can execute code on load. This is a remote code execution, but requires user action to open a notebook.
Patched in the following versions: 3.1.4, 3.0.17, 2.3.2, 2.2.10, 1.2.21.
OWASP Page on Restricting Form Submissions
If you have any questions or comments about this advisory, or vulnerabilities to report, please email our security list security@ipython.org.
Credit: Guillaume Jeanne from Google
{
"severity": "MODERATE",
"cwe_ids": [
"CWE-75",
"CWE-79",
"CWE-87"
],
"nvd_published_at": "2021-08-09T21:15:00Z",
"github_reviewed_at": "2021-08-23T16:41:37Z",
"github_reviewed": true
}