Search CVE reports


Toggle filters

1 – 10 of 18 results


CVE-2026-102831

Medium priority
Needs evaluation

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.5.0 until 4.5.11 and 4.6.4, from Notebook 7.5.0 until 7.6.3, and from JupyterLite...

2 affected packages

jupyter-notebook, jupyterlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jupyter-notebook Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
jupyterlab Needs evaluation Not in release Not in release — —
Show less packages

CVE-2026-40171

Medium priority
Needs evaluation

In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @jupyterlab/help-extension packages before 7.5.6 and 4.5.7, a stored cross-site...

1 affected package

jupyter-notebook

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jupyter-notebook Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-43805

Medium priority
Needs evaluation

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. This vulnerability depends on user interaction by opening a malicious notebook with Markdown cells, or...

2 affected packages

jupyterlab, jupyter-notebook

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jupyterlab Needs evaluation Not in release Not in release Not in release —
jupyter-notebook Not affected Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-22421

Medium priority
Ignored

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious link may get their `Authorization` and `XSRFToken`...

2 affected packages

jupyter-notebook, jupyterlab

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jupyter-notebook — Not affected Not affected Not affected Not affected
jupyterlab — Not in release Not in release Not in release —
Show less packages

CVE-2024-22420

Medium priority
Not affected

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. This vulnerability depends on user interaction by opening a malicious Markdown file using...

1 affected package

jupyter-notebook

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jupyter-notebook — — Not affected Not affected Not affected
Show less packages

CVE-2023-35394

Medium priority
Ignored

Azure HDInsight Jupyter Notebook Spoofing Vulnerability

3 affected packages

jupyter-core, jupyter-notebook, notebook

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jupyter-core — Not affected Not affected Not affected Not affected
jupyter-notebook — Not affected Not affected Not affected Not affected
notebook — Not in release Not in release Not in release Not affected
Show less packages

CVE-2022-25887

Medium priority

Some fixes available 4 of 18

The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.

2 affected packages

node-sanitize-html, jupyter-notebook

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-sanitize-html Needs evaluation Needs evaluation Needs evaluation Not in release Not in release
jupyter-notebook Vulnerable Fixed Fixed Not affected Not affected
Show less packages

CVE-2022-29238

Medium priority

Some fixes available 2 of 5

Jupyter Notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.12, authenticated requests to the notebook server with `ContentsManager.allow_hidden = False` only prevented listing the contents...

1 affected package

jupyter-notebook

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jupyter-notebook — — Fixed Fixed Not affected
Show less packages

CVE-2022-24758

Medium priority

Some fixes available 3 of 6

The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized actors can access sensitive information from server logs. Anytime a 5xx error is triggered, the auth cookie...

1 affected package

jupyter-notebook

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jupyter-notebook — — Fixed Fixed Fixed
Show less packages

CVE-2021-32798

Medium priority
Vulnerable

The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load. Jupyter Notebook uses a deprecated version of Google Caja to sanitize user...

1 affected package

jupyter-notebook

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jupyter-notebook Not affected Not affected Not affected Needs evaluation Vulnerable
Show less packages