{"schema_version":"1.7.3","id":"PYSEC-2021-118","published":"2021-08-09T21:15:00Z","modified":"2023-12-06T01:01:15.856930Z","aliases":["BIT-jupyter-base-notebook-2021-32798","BIT-jupyter-notebook-2021-32798","CVE-2021-32798","GHSA-hwvq-6gjx-j797"],"details":"The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load. Jupyter Notebook uses a deprecated version of Google Caja to sanitize user inputs. A public Caja bypass can be used to trigger an XSS when a victim opens a malicious ipynb document in Jupyter Notebook. The XSS allows an attacker to execute arbitrary code on the victim computer using Jupyter APIs.","affected":[{"package":{"name":"notebook","ecosystem":"PyPI","purl":"pkg:pypi/notebook"},"ranges":[{"type":"GIT","repo":"https://github.com/jupyter/notebook","events":[{"introduced":"0"},{"fixed":"79fc76e890a8ec42f73a3d009e44ef84c14ef0d5"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.7.0"},{"fixed":"5.7.11"}]}],"versions":["5.7.0","5.7.1","5.7.10","5.7.2","5.7.3","5.7.4","5.7.5","5.7.6","5.7.8","5.7.9"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/notebook/PYSEC-2021-118.yaml"}}],"references":[{"type":"ADVISORY","url":"https://github.com/jupyter/notebook/security/advisories/GHSA-hwvq-6gjx-j797"},{"type":"FIX","url":"https://github.com/jupyter/notebook/commit/79fc76e890a8ec42f73a3d009e44ef84c14ef0d5"}]}