© 2025-2026 PySpect
First version without a known vulnerability: 7.0.0a1
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
Fixed in: 4.5.7, 7.5.6
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
Fixed in: 7.5.6, 4.5.7
HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering
Fixed in: 3.6.8, 7.2.2, 4.2.5
JupyterLab vulnerable to potential authentication and CSRF tokens leak
Fixed in: 4.0.11, 3.6.7, 7.0.7
JupyterLab vulnerable to SXSS in Markdown Preview
Fixed in: 4.0.11, 7.0.7
Token bruteforcing.
Fixed in: 6.4.12
Improper Input Validation in Jupyter Notebook
Fixed in: 4.0.5, 3.2.2, 9e63dd89b603dfbe3a7e774d8a962ee0fa30c0b5
Improper Neutralization of Input During Web Page Generation in Jupyter Notebook
Fixed in: 4.0.5, 3.2.2, 35f32dd2da804d108a3a3585b69ec3295b2677ed, dd9876381f0ef09873d8c5f6f2063269172331e3
Improper Neutralization of Input During Web Page Generation in Jupyter Notebook
Fixed in: 5.7.6
Sensitive Auth & Cookie data stored in Jupyter server logs
Fixed in: 6.4.10
Special Element Injection in notebook
Fixed in: 5.7.11, 6.4.1, 79fc76e890a8ec42f73a3d009e44ef84c14ef0d5
JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>
Fixed in: 1.2.21, 2.2.10, 2.3.2, 3.0.17, 3.1.4, 5.7.11, 6.4.1
Open redirect in Jupyter Notebook
Fixed in: 6.1.5, 3cec4bbe21756de9f0c4bccf18cf61d840314d74
Cross-site scripting in Jupyter Notebook
Fixed in: 5.5.0rc1, 5.5.0
Jupyter Notebook open redirect vulnerability
Fixed in: 5.7.8
Open Redirect vulnerability in jupyterhub and notebook
Fixed in: 5.7.8, 0.9.6
Jupyter Notebook XSS via directory name
Fixed in: 5.7.2, 288b73e1edbf527740e273fcc69b889460871648
Jupyter Notebook XSS via untrusted notebooks
Fixed in: 5.7.1, 107a89fce5f413fb5728c1c5d2c7788e1fb17491
Jupyter Notebook file bypasses sanitization, executes JavaScript
Fixed in: 5.4.1