Description
JupyterLab is a user interface for Project Jupyter which will eventually replace the classic Jupyter Notebook. In affected versions untrusted notebook can execute code on load. In particular JupyterLab doesn’t sanitize the action attribute of html `<form>`. Using this it is possible to trigger the form validation outside of the form itself. This is a remote code execution, but requires user action to open a notebook.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0107 | JupyterLab is a user interface for Project Jupyter which will eventually replace the classic Jupyter Notebook. In affected versions untrusted notebook can execute code on load. In particular JupyterLab doesn’t sanitize the action attribute of html `<form>`. Using this it is possible to trigger the form validation outside of the form itself. This is a remote code execution, but requires user action to open a notebook. |
Github GHSA |
GHSA-4952-p58q-6crx | JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form> |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-03T23:33:56.163Z
Reserved: 2021-05-12T00:00:00.000Z
Link: CVE-2021-32797
No data.
Status : Modified
Published: 2021-08-09T21:15:08.140
Modified: 2024-11-21T06:07:45.790
Link: CVE-2021-32797
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA