Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server
Published Nov 18, 2018
5.1
MEDIUMCVSS 4.0
EPSS 1.51%
Description
Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconvert endpoints can execute JavaScript with access to the server API. In notebook/nbconvert/handlers.py, NbconvertFileHandler and NbconvertPostHandler do not set a Content Security Policy to prevent this.
Affected products
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
AV:N/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.51% (0.01511) | 73.52th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.51% (0.01511) | 71.06th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.18% (0.00182) | 37.74th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.13% (0.00131) | 49.66th | v3 (v2023.03.01) |
| Nov 12, 2023 | 0.18% (0.00183) | 55.44th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.23% (0.00230) | 60.53th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.19% (0.00190) | 54.74th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.02% (0.01018) | 40.69th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.02% (0.01018) | 19.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.25% (0.01247) | 30.57th | v5 (v2026.06.15) |
| Apr 14, 2021 | 1.25% (0.01247) | 0.00th | v1 |
References (9)
- https://github.com/advisories/GHSA-49qr-xh3w-h436 Advisory
- https://github.com/jupyter/notebook/blob/master/docs/source/changelog.rst x_refsource_MISCRelease Notes
- https://github.com/jupyter/notebook/commit/107a89fce5f413fb5728c1c5d2c7788e1fb17491 x_refsource_MISCPatchThird Party Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/notebook/PYSEC-2018-17.yaml
- https://groups.google.com/forum/#!topic/jupyter/hWzu2BSsplY
- https://groups.google.com/forum/#%21topic/jupyter/hWzu2BSsplY x_refsource_MISC
- https://lists.debian.org/debian-lts-announce/2020/11/msg00033.html mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2018-19351
- https://pypi.org/project/notebook/#history x_refsource_MISCThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-49qr-xh3w-h436 | Advisory | |
| https://github.com/jupyter/notebook/blob/master/docs/source/changelog.rst | x_refsource_MISCRelease Notes | |
| https://github.com/jupyter/notebook/commit/107a89fce5f413fb5728c1c5d2c7788e1fb17491 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/pypa/advisory-database/tree/main/vulns/notebook/PYSEC-2018-17.yaml | ||
| https://groups.google.com/forum/#!topic/jupyter/hWzu2BSsplY | ||
| https://groups.google.com/forum/#%21topic/jupyter/hWzu2BSsplY | x_refsource_MISC | |
| https://lists.debian.org/debian-lts-announce/2020/11/msg00033.html | mailing-listx_refsource_MLIST | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-19351 | ||
| https://pypi.org/project/notebook/#history | x_refsource_MISCThird Party Advisory |
Change history (0)
No recorded changes yet.