Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. jupyterlab
  4. ›
  5. CVE-2021-32797

CVE-2021-32797: JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>

August 23, 2021 (updated November 18, 2024)

Untrusted notebook can execute code on load. This is a remote code execution, but requires user action to open a notebook.

References

  • github.com/advisories/GHSA-4952-p58q-6crx
  • github.com/google/security-research/security/advisories/GHSA-c469-p3jp-2vhx
  • github.com/jupyterlab/jupyterlab/commit/504825938c0abfa2fb8ff8d529308830a5ae42ed
  • github.com/jupyterlab/jupyterlab/security/advisories/GHSA-4952-p58q-6crx
  • github.com/pypa/advisory-database/tree/main/vulns/jupyterlab/PYSEC-2021-130.yaml
  • nvd.nist.gov/vuln/detail/CVE-2021-32797

Code Behaviors & Features

Detect and mitigate CVE-2021-32797 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 2.0.0a0 before 2.2.10, all versions starting from 2.3.0a0 before 2.3.2, all versions starting from 3.0.0a0 before 3.0.17, all versions starting from 3.1.0a0 before 3.1.4, all versions before 1.2.21

Fixed versions

  • 1.2.21
  • 2.2.10
  • 2.3.2
  • 3.0.17
  • 3.1.4

Solution

Upgrade to versions 1.2.21, 2.2.10, 2.3.2, 3.0.17, 3.1.4 or above.

Impact 9.6 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-75: Failure to Sanitize Special Elements into a Different Plane (Special Element Injection)
  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
  • CWE-87: Improper Neutralization of Alternate XSS Syntax

Source file

pypi/jupyterlab/CVE-2021-32797.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:48 +0000.