{"id":"CVE-2021-32798","details":"The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load. Jupyter Notebook uses a deprecated version of Google Caja to sanitize user inputs. A public Caja bypass can be used to trigger an XSS when a victim opens a malicious ipynb document in Jupyter Notebook. The XSS allows an attacker to execute arbitrary code on the victim computer using Jupyter APIs.","aliases":["BIT-jupyter-base-notebook-2021-32798","BIT-jupyter-notebook-2021-32798","GHSA-hwvq-6gjx-j797","PYSEC-2021-118"],"modified":"2026-02-11T14:32:53.051362Z","published":"2021-08-09T21:15:08.233Z","related":["GHSA-hwvq-6gjx-j797","openSUSE-SU-2024:0231-1"],"references":[{"type":"ADVISORY","url":"https://github.com/jupyter/notebook/commit/79fc76e890a8ec42f73a3d009e44ef84c14ef0d5"},{"type":"ADVISORY","url":"https://github.com/jupyter/notebook/security/advisories/GHSA-hwvq-6gjx-j797"},{"type":"EVIDENCE","url":"https://github.com/jupyter/notebook/commit/79fc76e890a8ec42f73a3d009e44ef84c14ef0d5"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/jupyter/notebook","events":[{"introduced":"0"},{"fixed":"79fc76e890a8ec42f73a3d009e44ef84c14ef0d5"},{"introduced":"775cb20de3dc273f1fc31cd55d895e16dfe98bdf"},{"fixed":"79fc76e890a8ec42f73a3d009e44ef84c14ef0d5"}]}],"versions":["5.7.0","6.0.0","6.0.0rc1","6.0.1","6.0.2","6.0.3","6.1.0","6.1.0rc1","6.1.1","6.1.2","6.1.3","6.1.4","6.2.0","6.3.0","v6.4.0","v6.4.0rc0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-32798.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"}]}