{"schema_version":1,"title":"notebook (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 19 vulnerabilities in notebook (PyPI): 0 in the last 7 days and 7 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-40171, was published on 13 July 2026.","url":"https://junglewise.ai/threats/technologies/pypi-notebook","json_url":"https://junglewise.ai/threats/technologies/pypi-notebook.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/pypi-notebook","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":19,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":7,"last_365_days":8},"latest":[{"cve":"CVE-2026-40171","cvss":4,"epss":0.0066,"slug":"cve-2026-40171-jupyter-notebook-authentication-token-theft-via-commandlinker-xss","title":"PYSEC-2026-2682 - Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS","severity":"medium","exploited":false,"published_at":"2026-07-13T15:02:55.67876+00:00","url":"https://junglewise.ai/threats/cve-2026-40171-jupyter-notebook-authentication-token-theft-via-commandlinker-xss"},{"cve":"CVE-2024-43805","cvss":3.1,"epss":0.004,"slug":"cve-2024-43805-html-injection-in-jupyter-notebook-and-jupyterlab-leading-to-dom","title":"PYSEC-2026-2536 - HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering","severity":"low","exploited":false,"published_at":"2026-07-13T14:36:32.612035+00:00","url":"https://junglewise.ai/threats/cve-2024-43805-html-injection-in-jupyter-notebook-and-jupyterlab-leading-to-dom"},{"cve":"CVE-2024-22421","cvss":3.1,"epss":0.0067,"slug":"cve-2024-22421-jupyterlab-vulnerable-to-potential-authentication-and-csrf-tokens","title":"PYSEC-2026-2534 - JupyterLab vulnerable to potential authentication and CSRF tokens leak","severity":"low","exploited":false,"published_at":"2026-07-13T14:20:02.685378+00:00","url":"https://junglewise.ai/threats/cve-2024-22421-jupyterlab-vulnerable-to-potential-authentication-and-csrf-tokens"},{"cve":"CVE-2024-22420","cvss":3.1,"epss":0.0057,"slug":"cve-2024-22420-jupyterlab-vulnerable-to-sxss-in-markdown-preview","title":"PYSEC-2026-2535 - JupyterLab vulnerable to SXSS in Markdown Preview","severity":"low","exploited":false,"published_at":"2026-07-13T14:20:02.558089+00:00","url":"https://junglewise.ai/threats/cve-2024-22420-jupyterlab-vulnerable-to-sxss-in-markdown-preview"},{"cve":"CVE-2019-9644","cvss":3,"epss":0.0153,"slug":"cve-2019-9644-improper-neutralization-of-input-during-web-page-generation-in","title":"PYSEC-2026-2531 - Improper Neutralization of Input During Web Page Generation in Jupyter Notebook","severity":"low","exploited":false,"published_at":"2026-07-09T16:49:45.846184+00:00","url":"https://junglewise.ai/threats/cve-2019-9644-improper-neutralization-of-input-during-web-page-generation-in"},{"cve":"CVE-2021-32797","cvss":3.1,"epss":0.0266,"slug":"cve-2021-32797-jupyterlab-xss-due-to-lack-of-sanitization-of-the-action","title":"PYSEC-2026-688 - JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:10.480332+00:00","url":"https://junglewise.ai/threats/cve-2021-32797-jupyterlab-xss-due-to-lack-of-sanitization-of-the-action"},{"cve":"CVE-2019-10255","cvss":3,"epss":0.0176,"slug":"cve-2019-10255-open-redirect-vulnerability-in-jupyterhub-and-notebook","title":"PYSEC-2026-647 - Open Redirect vulnerability in jupyterhub and notebook","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:09.322452+00:00","url":"https://junglewise.ai/threats/cve-2019-10255-open-redirect-vulnerability-in-jupyterhub-and-notebook"},{"cve":"CVE-2026-42557","cvss":9.6,"epss":0.0072,"slug":"cve-2026-42557-jupyter-jupyterlab-arbitrary-command-execution-via-html-sanitizer","title":"Jupyter JupyterLab arbitrary command execution via HTML sanitizer bypass","severity":"critical","exploited":false,"published_at":"2026-05-13T16:16:48.167+00:00","url":"https://junglewise.ai/threats/cve-2026-42557-jupyter-jupyterlab-arbitrary-command-execution-via-html-sanitizer"},{"cve":"CVE-2022-29238","cvss":3.1,"epss":0.0108,"slug":"cve-2022-29238-token-bruteforcing","title":"PYSEC-2022-212 - Jupyter Notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.12, authenticated requests to the noteb","severity":"low","exploited":false,"published_at":"2022-06-14T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-29238-token-bruteforcing"},{"cve":"CVE-2022-24758","cvss":3.1,"epss":0.011,"slug":"cve-2022-24758-sensitive-auth-cookie-data-stored-in-jupyter-server-logs","title":"PYSEC-2022-180 - The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized actors can access s","severity":"low","exploited":false,"published_at":"2022-03-31T23:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-24758-sensitive-auth-cookie-data-stored-in-jupyter-server-logs"},{"cve":"CVE-2021-32798","cvss":3.1,"epss":0.0211,"slug":"cve-2021-32798-special-element-injection-in-notebook","title":"PYSEC-2021-118 - The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code","severity":"low","exploited":false,"published_at":"2021-08-09T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-32798-special-element-injection-in-notebook"},{"cve":"CVE-2020-26215","cvss":3.1,"epss":0.0123,"slug":"cve-2020-26215-open-redirect-in-jupyter-notebook","title":"PYSEC-2020-215 - Jupyter Notebook before version 6.1.5 has an Open redirect vulnerability. A maliciously crafted link to a notebook server could redirect the","severity":"low","exploited":false,"published_at":"2020-11-18T22:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-26215-open-redirect-in-jupyter-notebook"},{"cve":"CVE-2018-21030","cvss":3.1,"epss":0.0144,"slug":"cve-2018-21030-cross-site-scripting-in-jupyter-notebook","title":"PYSEC-2019-157 - Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS p","severity":"low","exploited":false,"published_at":"2019-10-31T15:15:00+00:00","url":"https://junglewise.ai/threats/cve-2018-21030-cross-site-scripting-in-jupyter-notebook"},{"cve":"CVE-2019-10856","cvss":3,"epss":0.0126,"slug":"cve-2019-10856-jupyter-notebook-open-redirect-vulnerability","title":"PYSEC-2019-158 - In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists because of an incomplete fix for CVE-201","severity":"low","exploited":false,"published_at":"2019-04-04T16:29:00+00:00","url":"https://junglewise.ai/threats/cve-2019-10856-jupyter-notebook-open-redirect-vulnerability"},{"cve":"CVE-2018-19352","cvss":3,"epss":0.0134,"slug":"cve-2018-19352-jupyter-notebook-xss-via-directory-name","title":"PYSEC-2018-18 - Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles certain URLs u","severity":"low","exploited":false,"published_at":"2018-11-18T17:29:00+00:00","url":"https://junglewise.ai/threats/cve-2018-19352-jupyter-notebook-xss-via-directory-name"},{"cve":"CVE-2018-19351","cvss":3,"epss":0.0151,"slug":"cve-2018-19351-jupyter-notebook-xss-via-untrusted-notebooks","title":"PYSEC-2018-17 - Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the","severity":"low","exploited":false,"published_at":"2018-11-18T17:29:00+00:00","url":"https://junglewise.ai/threats/cve-2018-19351-jupyter-notebook-xss-via-untrusted-notebooks"},{"cve":"CVE-2018-8768","cvss":3,"epss":0.0107,"slug":"cve-2018-8768-jupyter-notebook-file-bypasses-sanitization-executes-javascript","title":"PYSEC-2018-57 - In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context.","severity":"low","exploited":false,"published_at":"2018-03-18T06:29:00+00:00","url":"https://junglewise.ai/threats/cve-2018-8768-jupyter-notebook-file-bypasses-sanitization-executes-javascript"},{"cve":"CVE-2015-7337","cvss":3.1,"epss":0.0249,"slug":"cve-2015-7337-improper-input-validation-in-jupyter-notebook","title":"PYSEC-2015-27 - The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript","severity":"low","exploited":false,"published_at":"2015-09-29T19:59:00+00:00","url":"https://junglewise.ai/threats/cve-2015-7337-improper-input-validation-in-jupyter-notebook"},{"cve":"CVE-2015-6938","cvss":3.1,"epss":0.0279,"slug":"cve-2015-6938-improper-neutralization-of-input-during-web-page-generation-in","title":"PYSEC-2015-26 - Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Noteboo","severity":"low","exploited":false,"published_at":"2015-09-21T19:59:00+00:00","url":"https://junglewise.ai/threats/cve-2015-6938-improper-neutralization-of-input-during-web-page-generation-in"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"notebook (PyPI)","slug":"pypi-notebook","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"description":"Python interactive notebook environment for executing code, creating visualizations, and sharing analysis.","url":"https://junglewise.ai/threats/technologies/pypi-notebook"},"most_severe":[{"cve":"CVE-2026-42557","cvss":9.6,"epss":0.0072,"slug":"cve-2026-42557-jupyter-jupyterlab-arbitrary-command-execution-via-html-sanitizer","title":"Jupyter JupyterLab arbitrary command execution via HTML sanitizer bypass","severity":"critical","exploited":false,"published_at":"2026-05-13T16:16:48.167+00:00","url":"https://junglewise.ai/threats/cve-2026-42557-jupyter-jupyterlab-arbitrary-command-execution-via-html-sanitizer"},{"cve":"CVE-2026-40171","cvss":4,"epss":0.0066,"slug":"cve-2026-40171-jupyter-notebook-authentication-token-theft-via-commandlinker-xss","title":"PYSEC-2026-2682 - Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS","severity":"medium","exploited":false,"published_at":"2026-07-13T15:02:55.67876+00:00","url":"https://junglewise.ai/threats/cve-2026-40171-jupyter-notebook-authentication-token-theft-via-commandlinker-xss"},{"cve":"CVE-2015-6938","cvss":3.1,"epss":0.0279,"slug":"cve-2015-6938-improper-neutralization-of-input-during-web-page-generation-in","title":"PYSEC-2015-26 - Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Noteboo","severity":"low","exploited":false,"published_at":"2015-09-21T19:59:00+00:00","url":"https://junglewise.ai/threats/cve-2015-6938-improper-neutralization-of-input-during-web-page-generation-in"},{"cve":"CVE-2021-32797","cvss":3.1,"epss":0.0266,"slug":"cve-2021-32797-jupyterlab-xss-due-to-lack-of-sanitization-of-the-action","title":"PYSEC-2026-688 - JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:10.480332+00:00","url":"https://junglewise.ai/threats/cve-2021-32797-jupyterlab-xss-due-to-lack-of-sanitization-of-the-action"},{"cve":"CVE-2015-7337","cvss":3.1,"epss":0.0249,"slug":"cve-2015-7337-improper-input-validation-in-jupyter-notebook","title":"PYSEC-2015-27 - The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript","severity":"low","exploited":false,"published_at":"2015-09-29T19:59:00+00:00","url":"https://junglewise.ai/threats/cve-2015-7337-improper-input-validation-in-jupyter-notebook"},{"cve":"CVE-2021-32798","cvss":3.1,"epss":0.0211,"slug":"cve-2021-32798-special-element-injection-in-notebook","title":"PYSEC-2021-118 - The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code","severity":"low","exploited":false,"published_at":"2021-08-09T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-32798-special-element-injection-in-notebook"},{"cve":"CVE-2018-21030","cvss":3.1,"epss":0.0144,"slug":"cve-2018-21030-cross-site-scripting-in-jupyter-notebook","title":"PYSEC-2019-157 - Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS p","severity":"low","exploited":false,"published_at":"2019-10-31T15:15:00+00:00","url":"https://junglewise.ai/threats/cve-2018-21030-cross-site-scripting-in-jupyter-notebook"},{"cve":"CVE-2020-26215","cvss":3.1,"epss":0.0123,"slug":"cve-2020-26215-open-redirect-in-jupyter-notebook","title":"PYSEC-2020-215 - Jupyter Notebook before version 6.1.5 has an Open redirect vulnerability. A maliciously crafted link to a notebook server could redirect the","severity":"low","exploited":false,"published_at":"2020-11-18T22:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-26215-open-redirect-in-jupyter-notebook"},{"cve":"CVE-2022-24758","cvss":3.1,"epss":0.011,"slug":"cve-2022-24758-sensitive-auth-cookie-data-stored-in-jupyter-server-logs","title":"PYSEC-2022-180 - The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized actors can access s","severity":"low","exploited":false,"published_at":"2022-03-31T23:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-24758-sensitive-auth-cookie-data-stored-in-jupyter-server-logs"},{"cve":"CVE-2022-29238","cvss":3.1,"epss":0.0108,"slug":"cve-2022-29238-token-bruteforcing","title":"PYSEC-2022-212 - Jupyter Notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.12, authenticated requests to the noteb","severity":"low","exploited":false,"published_at":"2022-06-14T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-29238-token-bruteforcing"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}