{"id":"BIT-jupyter-notebook-2021-32798","summary":"Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in notebook","details":"The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load. Jupyter Notebook uses a deprecated version of Google Caja to sanitize user inputs. A public Caja bypass can be used to trigger an XSS when a victim opens a malicious ipynb document in Jupyter Notebook. The XSS allows an attacker to execute arbitrary code on the victim computer using Jupyter APIs.","aliases":["BIT-jupyter-base-notebook-2021-32798","CVE-2021-32798","GHSA-hwvq-6gjx-j797","PYSEC-2021-118"],"modified":"2026-09-08T08:47:30.384042839Z","published":"2024-03-06T10:54:36.287Z","database_specific":{"severity":"Critical","cpes":["cpe:2.3:a:jupyter:notebook:*:*:*:*:*:*:*:*","cpe:2.3:a:jupyter:notebook:6.4.0:*:*:*:*:*:*:*"]},"references":[{"type":"ADVISORY","url":"https://github.com/jupyter/notebook/commit/79fc76e890a8ec42f73a3d009e44ef84c14ef0d5"},{"type":"ADVISORY","url":"https://github.com/jupyter/notebook/security/advisories/GHSA-hwvq-6gjx-j797"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-32798"}],"affected":[{"package":{"name":"jupyter-notebook","ecosystem":"Bitnami","purl":"pkg:bitnami/jupyter-notebook"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.7.0"},{"fixed":"5.7.11"},{"introduced":"6.4.0"},{"fixed":"6.4.1"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/jupyter-notebook/BIT-jupyter-notebook-2021-32798.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"}]}],"schema_version":"1.9.0"}