Jupyter Notebook Vulnerability Allows Malicious JavaScript Execution
CVE-2018-8768
7.8HIGH
What is CVE-2018-8768?
In Jupyter Notebook prior to version 5.4.1, a vulnerability exists that allows a maliciously forged notebook file to bypass normal sanitization processes. This flaw may lead to unintended JavaScript execution within the notebook context. The improper handling of invalid HTML allows content to be 'fixed' by jQuery after sanitization, rendering the system susceptible to attacks that exploit this behavior.
