CVE-2014-3429: Ipython Notebook

Medium severity, CVSS 6.8. EPSS: 4.7% chance of exploitation in the next 30 days.

IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page.

Affected products

  • Ipython Ipython Notebook: version 0.12 only; version 0.12.1 only; version 0.13 only; version 0.13.1 only; version 0.13.2 only; version 1.0.0 only; …
  • Mageia Mageia: version 3.0 only; version 4.0 only
  • Opensuse Opensuse: version 13.1 only; version 13.2 only

Published 2014-08-07. Last modified 2026-06-17.