---
id: CVE-2021-42952
title: >-
  Zepl Notebooks before 2021-10-25 are affected by a sandbox escape
  vulnerability
summary: >-
  Zepl Notebooks before 2021-10-25 are affected by a sandbox escape
  vulnerability. Upon launching Remote Code Execution from the Notebook, users
  can then use that to subsequently escape the running context sandbox and
  proceed to access int…
severity: critical
cvss: 9.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
vendor: zepl
product: zepl
affected:
  - zepl < 2021-10-25
patched:
  - zepl 2021-10-25
published: '2022-02-25'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-42952'
references:
  - url: 'https://seclists.org/fulldisclosure/2022/Feb/32'
    label: cve@mitre.org
  - url: 'http://zepl.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://seclists.org/fulldisclosure/2022/Feb/32'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01571
epssPercentile: 0.7433
ingestedAt: '2026-07-06T17:03:23.909Z'
---

## Overview

Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability. Upon launching Remote Code Execution from the Notebook, users can then use that to subsequently escape the running context sandbox and proceed to access internal Zepl assets including cloud metadata services.

## Affected

- `zepl < 2021-10-25`

## Remediation

Upgrade past the affected range:

- `zepl 2021-10-25`
