{"id":"CVE-2021-32862","aliases":["GHSA-9jmq-rx5f-8jwq","GHSA-h274-fcvj-h2wm","PYSEC-2022-249"],"url":"https://o3.security/vulnerability/CVE-2021-32862","summary":"nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths","details":"The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using nbconvert to generate an HTML version of a user-controllable notebook, it is possible to inject arbitrary HTML which may lead to cross-site scripting (XSS) vulnerabilities if these HTML notebooks are served by a web server (eg: nbviewer).","published":"2022-08-18T19:15:14.337Z","modified":"2026-07-08T05:57:17.836017436Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"nbconvert","fixedVersion":"6.5.1"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/09/msg00004.html"},{"type":"ADVISORY","url":"https://github.com/jupyter/nbviewer/security/advisories/GHSA-h274-fcvj-h2wm"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2023/06/msg00003.html"},{"type":"EVIDENCE","url":"https://github.com/jupyter/nbconvert/security/advisories/GHSA-9jmq-rx5f-8jwq"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:57:17.836017436Z"}}