VYPR
Unrated severityNVD Advisory· Published Jun 27, 2026

Debian nbconvert: A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows for Cross-site Sc…

CVE-2026-6658

Description

A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows for Cross-site Scripting (XSS) via unsanitized text/vnd.mermaid output in HTML exports. The data_mermaid block in share/templates/lab/base.html.j2 renders text/vnd.mermaid cell output directly into HTML without escaping, enabling attackers to inject arbitrary HTML/JavaScript by breaking out of the `` tag. This vulnerability impacts any server using nbconvert to render notebooks as HTML, allowing attackers to execute arbitrary JavaScript in the context of users viewing the HTML export.

Affected products

1

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.