High severity7.4NVD Advisory· Published Aug 9, 2021· Updated Jun 17, 2026
CVE-2021-32797
CVE-2021-32797
Description
JupyterLab is a user interface for Project Jupyter which will eventually replace the classic Jupyter Notebook. In affected versions untrusted notebook can execute code on load. In particular JupyterLab doesn’t sanitize the action attribute of html ``. Using this it is possible to trigger the form validation outside of the form itself. This is a remote code execution, but requires user action to open a notebook.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
jupyterlabPyPI | < 1.2.21 | 1.2.21 |
jupyterlabPyPI | >= 2.0.0a0, < 2.2.10 | 2.2.10 |
jupyterlabPyPI | >= 2.3.0a0, < 2.3.2 | 2.3.2 |
jupyterlabPyPI | >= 3.0.0a0, < 3.0.17 | 3.0.17 |
jupyterlabPyPI | >= 3.1.0a0, < 3.1.4 | 3.1.4 |
notebookPyPI | < 5.7.11 | 5.7.11 |
notebookPyPI | >= 6.0.0, < 6.4.1 | 6.4.1 |
Affected products
7>= 3.1.0, < 3.1.4+ 1 more
- (no CPE)range: >= 3.1.0, < 3.1.4
- cpe:2.3:a:jupyter:jupyterlab:*:*:*:*:*:*:*:*range: <1.2.21
- osv-coords5 versionspkg:rpm/suse/python-jupyterlab&distro=SUSE%20Package%20Hub%2015%20SP4pkg:bitnami/jupyterlabpkg:rpm/opensuse/python-jupyterlab&distro=openSUSE%20Leap%2015.4pkg:pypi/jupyterlabpkg:pypi/notebook
< 2.2.10-bp154.2.3.1+ 4 more
- (no CPE)range: < 2.2.10-bp154.2.3.1
- (no CPE)range: < 1.2.21
- (no CPE)range: < 2.2.10-bp154.2.3.1
- (no CPE)range: < 1.2.21
- (no CPE)range: < 5.7.11
Patches
Vulnerability mechanics
References
6- github.com/jupyterlab/jupyterlab/commit/504825938c0abfa2fb8ff8d529308830a5ae42ednvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-4952-p58q-6crxghsaADVISORY
- github.com/jupyterlab/jupyterlab/security/advisories/GHSA-4952-p58q-6crxnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-32797ghsaADVISORY
- github.com/google/security-research/security/advisories/GHSA-c469-p3jp-2vhxghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/jupyterlab/PYSEC-2021-130.yamlghsaWEB
News mentions
0No linked articles in our index yet.