Meet Corgea at Black Hat, BSides Las Vegas & DEF CON
HIGH 7.8 PyPI

Jupyter Notebook file bypasses sanitization, executes JavaScript

GHSA-6cwv-x26c-w2q4 · CVE-2018-8768 · PYSEC-2018-57

Published · Modified

Description

In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by jQuery after sanitization, making it dangerous.

Ready to move

Start Securing

Free, no credit card | First findings in minutes