The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load. Jupyter Notebook uses a deprecated version of Google Caja to sanitize user inputs. A public Caja bypass can be used to trigger an XSS when a victim opens a malicious ipynb document in Jupyter Notebook. The XSS allows an attacker to execute arbitrary code on the victim computer using Jupyter APIs.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "jupyter-notebook", "binary_version": "6.4.8-1" }, { "binary_name": "python-notebook-doc", "binary_version": "6.4.8-1" }, { "binary_name": "python3-notebook", "binary_version": "6.4.8-1" } ], "ubuntu_priority": "medium" }