notebook vulnerabilities
CVEs whose affected-version data names the notebook package (npm, pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
10 CVEsRSS
CVE-2026-42557Critical· 9.6JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
CVE-2026-40171High· 8.8Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
CVE-2024-43805High· 7.6HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering
HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering
CVE-2024-22420Medium· 6.5JupyterLab vulnerable to SXSS in Markdown Preview
JupyterLab vulnerable to SXSS in Markdown Preview
CVE-2024-22421High· 7.6JupyterLab vulnerable to potential authentication and CSRF tokens leak
JupyterLab vulnerable to potential authentication and CSRF tokens leak
CVE-2019-9644Medium· 5.4Improper Neutralization of Input During Web Page Generation in Jupyter Notebook
Improper Neutralization of Input During Web Page Generation in Jupyter Notebook
CVE-2021-32798Critical· 10.0Special Element Injection in notebook
Special Element Injection in notebook
CVE-2021-32797High· 7.4JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>
JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>
CVE-2020-26215Medium· 4.4Open redirect in Jupyter Notebook
Open redirect in Jupyter Notebook
CVE-2019-10255Medium· 6.1Open Redirect vulnerability in jupyterhub and notebook
Open Redirect vulnerability in jupyterhub and notebook