VYPR

npm package

nbdime

pkg:npm/nbdime

Vulnerabilities (1)

  • CVE-2021-41134Nov 3, 2021
    affected < 5.0.2fixed 5.0.2

    nbdime provides tools for diffing and merging of Jupyter Notebooks. In affected versions a stored cross-site scripting (XSS) issue exists within the Jupyter-owned nbdime project. It appears that when reading the file name and path from disk, the extension does not sanitize the st