38 Total advisories
38 Vulnerabilities
0 Malware

Dependency scanning

Check whether notebook is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

CRITICAL 9.6
PyPI

CVE-2026-42557

JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content

UNKNOWN
npm

CVE-2026-40171

Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS

HIGH 7.6
PyPI

CVE-2024-22421

JupyterLab vulnerable to potential authentication and CSRF tokens leak

MEDIUM 6.5
PyPI

CVE-2024-22420

JupyterLab vulnerable to SXSS in Markdown Preview

CRITICAL 10.0
PyPI

CVE-2021-32798

Special Element Injection in notebook

MEDIUM 4.4
PyPI

CVE-2020-26215

Open redirect in Jupyter Notebook

MEDIUM 6.5
PyPI

CVE-2024-22420

JupyterLab vulnerable to SXSS in Markdown Preview

UNKNOWN
PyPI

CVE-2019-9644

CVE-2019-9644

MEDIUM 5.4
PyPI

CVE-2019-9644

Improper Neutralization of Input During Web Page Generation in Jupyter Notebook

HIGH 7.6
PyPI

CVE-2024-43805

HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering

HIGH 7.6
PyPI

CVE-2024-43805

HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering

CRITICAL 9.6
PyPI

CVE-2026-42557

JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content

MEDIUM 6.1
PyPI

CVE-2019-10255

Open Redirect vulnerability in jupyterhub and notebook

MEDIUM 6.1
PyPI

CVE-2019-10255

Open Redirect vulnerability in jupyterhub and notebook

HIGH 7.6
PyPI

CVE-2024-22421

JupyterLab vulnerable to potential authentication and CSRF tokens leak

UNKNOWN
PyPI

CVE-2026-40171

Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS

HIGH 7.4
PyPI

CVE-2021-32797

JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>

HIGH 7.4
PyPI

CVE-2021-32797

JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>

UNKNOWN
PyPI

CVE-2022-29238

CVE-2022-29238

UNKNOWN
PyPI

CVE-2022-24758

CVE-2022-24758

UNKNOWN
PyPI

CVE-2020-26215

CVE-2020-26215

HIGH 7.8
PyPI

CVE-2018-8768

Jupyter Notebook file bypasses sanitization, executes JavaScript

MEDIUM 5.3
PyPI

CVE-2018-21030

Cross-site scripting in Jupyter Notebook

MEDIUM 6.1
PyPI

CVE-2018-19351

Jupyter Notebook XSS via untrusted notebooks

MEDIUM 6.1
PyPI

CVE-2018-19352

Jupyter Notebook XSS via directory name

MEDIUM 6.1
PyPI

CVE-2019-10856

Jupyter Notebook open redirect vulnerability

MEDIUM 6.1
PyPI

CVE-2015-6938

Improper Neutralization of Input During Web Page Generation in Jupyter Notebook

CRITICAL 9.8
PyPI

CVE-2015-7337

Improper Input Validation in Jupyter Notebook

MEDIUM 4.3
PyPI

CVE-2022-29238

Token bruteforcing.

HIGH 7.5
PyPI

CVE-2022-24758

Sensitive Auth & Cookie data stored in Jupyter server logs

UNKNOWN
PyPI

CVE-2021-32798

CVE-2021-32798

UNKNOWN
PyPI

CVE-2019-10856

CVE-2019-10856

UNKNOWN
PyPI

CVE-2018-8768

CVE-2018-8768

UNKNOWN
PyPI

CVE-2018-21030

CVE-2018-21030

UNKNOWN
PyPI

CVE-2018-19352

CVE-2018-19352

UNKNOWN
PyPI

CVE-2018-19351

CVE-2018-19351

UNKNOWN
PyPI

CVE-2015-7337

CVE-2015-7337

UNKNOWN
PyPI

CVE-2015-6938

CVE-2015-6938

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes