VYPR

npm package

nbdime-jupyterlab

pkg:npm/nbdime-jupyterlab

Vulnerabilities (1)

  • CVE-2021-41134Nov 3, 2021
    affected < 1.0.1fixed 1.0.1

    nbdime provides tools for diffing and merging of Jupyter Notebooks. In affected versions a stored cross-site scripting (XSS) issue exists within the Jupyter-owned nbdime project. It appears that when reading the file name and path from disk, the extension does not sanitize the st