{"id":"GHSA-gj55-2xf9-67rq","aliases":[],"url":"https://o3.security/vulnerability/GHSA-gj55-2xf9-67rq","summary":"HTML injection in JupyterLite leading to DOM Clobbering","details":"### Impact\n\nThe vulnerability depends on user interaction by opening a malicious notebook with Markdown cells, or Markdown file using JupyterLab preview feature.\n\nA malicious user can access any data accessible from JupyterLite and perform arbitrary actions in JupyterLite environment.\n\n### Patches\n\nJupyterLite 0.4.1 was patched.\n\n### Workarounds\n\nThere is no workaround for the underlying DOM Clobbering susceptibility. However, select plugins can be disabled on deployments which cannot update in a timely fashion to minimise the risk. These are:\n- `@jupyterlab/mathjax-extension:plugin` - users will loose ability to preview mathematical equations \n- `@jupyterlab/markdownviewer-extension:plugin` - users will loose ability to open Markdown previews\n- `@jupyterlab/mathjax2-extension:plugin` (if installed with optional `jupyterlab-mathjax2` package) - an older version of the mathjax plugin for JupyterLab 4.x\n\nTo disable these extensions populate the `disabledExtensions` key in `jupyter-config-data` stanza of `jupyter-lite.json` as documented on https://jupyterlite.readthedocs.io/en/stable/howto/configure/config_files.html#jupyter-lite-json\n\n```json\n{\n  \"jupyter-lite-schema-version\": 0,\n  \"jupyter-config-data\": {\n    \"appName\": \"My JupyterLite App\",\n    \"disabledExtensions\": [\n      \"@jupyterlab/markdownviewer-extension:plugin\",\n      \"@jupyterlab/mathjax-extension:plugin\",\n      \"@jupyterlab/mathjax2-extension:plugin\"\n    ]\n  }\n}\n```\n\nTo confirm that the plugins were disabled manual inspection of the built page is required.\n\n### References\n\nUpstream advisory: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-9q39-rmj3-p4r2\n\n### Notes\n\nThis change has a potential to break rendering of some markdown. There is a setting in Sanitizer which allows to revert to the previous sanitizer settings (`allowNamedProperties`).","published":"2024-09-06T19:51:19Z","modified":"2024-11-28T05:39:07.411996Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"jupyterlite-core","fixedVersion":"0.4.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-9q39-rmj3-p4r2"},{"type":"WEB","url":"https://github.com/jupyterlite/jupyterlite/security/advisories/GHSA-gj55-2xf9-67rq"},{"type":"PACKAGE","url":"https://github.com/jupyterlite/jupyterlite"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-28T05:39:07.411996Z"}}