Lucene search

K
osvGoogleOSV:PYSEC-2021-130
HistoryAug 09, 2021 - 9:15 p.m.

PYSEC-2021-130

2021-08-0921:15:00
Google
osv.dev
15
jupyterlab
untrusted notebooks
remote code execution
user interface
project jupyter
form validation

EPSS

0.004

Percentile

73.0%

JupyterLab is a user interface for Project Jupyter which will eventually replace the classic Jupyter Notebook. In affected versions untrusted notebook can execute code on load. In particular JupyterLab doesnโ€™t sanitize the action attribute of html <form>. Using this it is possible to trigger the form validation outside of the form itself. This is a remote code execution, but requires user action to open a notebook.