{"id":"CVE-2021-32798","aliases":["BIT-jupyter-base-notebook-2021-32798","BIT-jupyter-notebook-2021-32798","GHSA-hwvq-6gjx-j797","PYSEC-2021-118"],"url":"https://o3.security/vulnerability/CVE-2021-32798","summary":"Special Element Injection in notebook","details":"The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load. Jupyter Notebook uses a deprecated version of Google Caja to sanitize user inputs. A public Caja bypass can be used to trigger an XSS when a victim opens a malicious ipynb document in Jupyter Notebook. The XSS allows an attacker to execute arbitrary code on the victim computer using Jupyter APIs.","published":"2021-08-09T21:15:08.233Z","modified":"2026-08-07T17:02:07.227967Z","cvss":{"score":9.6,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"notebook","fixedVersion":"5.7.11"},{"ecosystem":"PyPI","name":"notebook","fixedVersion":"6.4.1"}],"fix":{"url":"https://github.com/jupyter/notebook/commit/79fc76e890a8ec42f73a3d009e44ef84c14ef0d5","label":"jupyter/notebook@79fc76e"},"references":[{"type":"ADVISORY","url":"https://github.com/jupyter/notebook/security/advisories/GHSA-hwvq-6gjx-j797"},{"type":"EVIDENCE","url":"https://github.com/jupyter/notebook/commit/79fc76e890a8ec42f73a3d009e44ef84c14ef0d5"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T17:02:07.227967Z"}}