Junglewise Threat Intelligence

CVE-2018-8768: PYSEC-2018-57 - In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context.

CVE-2018-8768 · Severity: low · CVSS 3 · Published 2018-03-18

Technologies: notebook (PyPI). Vendors: PyPI.

Executive brief

In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by jQuery after sanitization, making it dangerous.

Affected products

  • PyPI notebook

Related threats