Home/Product/jupyter notebook
Product

jupyter notebook

16 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-43805
>= 7.0.0 and < 7.2.2
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Th
7.6HIGH
CVE-2024-22421
>= 7.0.0 and < 7.0.7
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture
7.6HIGH
CVE-2024-22420
>= 7.0.0 and < 7.0.7
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture
6.5MEDIUM
CVE-2022-29238
< 6.4.12
Jupyter Notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.12, authenticated requests to
4.3MEDIUM
CVE-2022-24758
< 6.4.10
The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized actors ca
7.5HIGH
CVE-2021-32798
>= 5.7.0 and < 5.7.11
The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can ex
10.0CRITICAL
CVE-2020-26215
< 6.1.5
Jupyter Notebook before version 6.1.5 has an Open redirect vulnerability. A maliciously crafted link to a notebook server could re
4.4MEDIUM
CVE-2018-21030
< 5.5.0
Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example
5.3MEDIUM
CVE-2019-10856
< 5.7.8
In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists because of an incomplete fix f
6.1MEDIUM
CVE-2019-10255
< 5.7.7
An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub
6.1MEDIUM
CVE-2019-9644
< 5.7.6
An XSSI (cross-site inclusion) vulnerability in Jupyter Notebook before 5.7.6 allows inclusion of resources on malicious pages whe
5.4MEDIUM
CVE-2018-19352
< 5.7.2
Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles cert
6.1MEDIUM
CVE-2018-19351
< 5.7.1
Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same ori
6.1MEDIUM
CVE-2018-8768
< 5.4.1
In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook
7.8HIGH
CVE-2015-7337
all versions
The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary J
CVE-2015-6938
all versions
Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyt
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin