---
id: CVE-2021-42950
title: >-
  Remote Code Execution (RCE) vulnerability exists in Zepl Notebooks all
  previous versions before October 25 2021
summary: >-
  Remote Code Execution (RCE) vulnerability exists in Zepl Notebooks all
  previous versions before October 25 2021. Users can register for an account
  and are allocated a set number of credits to try the product. Once users
  authenticate, the…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: zepl
product: zepl
affected:
  - zepl < 2021-10-25
patched:
  - zepl 2021-10-25
published: '2022-03-03'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-42950'
references:
  - url: 'https://seclists.org/fulldisclosure/2022/Feb/31'
    label: cve@mitre.org
  - url: 'http://zepl.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://seclists.org/fulldisclosure/2022/Feb/31'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01571
epssPercentile: 0.74307
ingestedAt: '2026-07-06T17:03:23.936Z'
---

## Overview

Remote Code Execution (RCE) vulnerability exists in Zepl Notebooks all previous versions before October 25 2021. Users can register for an account and are allocated a set number of credits to try the product. Once users authenticate, they can proceed to create a new organization by which additional users can be added for various collaboration abilities, which allows malicious user to create new Zepl Notebooks with various languages, contexts, and deployment scenarios. Upon creating a new notebook with specially crafted malicious code, a user can then launch remote code execution.

## Affected

- `zepl < 2021-10-25`

## Remediation

Upgrade past the affected range:

- `zepl 2021-10-25`
