Executive brief
## Summary
When `HTMLExporter.embed_images=True`, nbconvert's markdown renderer allows arbitrary file read via path traversal in image references. A malicious notebook can exfiltrate sensitive files from the conversion host by embedding them as base64 data URIs in the output HTML.
## Patches
Upgrade to nbconvert 7.17.1
## Workarounds
Do not enable `HTMLExporter.embed_images` (it is not enabled by default).
Affected products
- PyPI nbconvert
References
- https://api.github.com/users/g0blinResearch
- https://github.com/g0blinResearch
- https://api.github.com/users/g0blinResearch/gists%7B/gist_id%7D
- https://api.github.com/users/g0blinResearch/repos
- https://avatars.githubusercontent.com/u/11961962?v=4
- https://api.github.com/users/g0blinResearch/events%7B/privacy%7D