CVE-2015-7337: Ipython Notebook

Medium severity, CVSS 6.8. EPSS: 2.5% chance of exploitation in the next 30 days.

The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/, related to MIME types.

Affected products

  • Ipython Notebook: up to and including 3.2.1
  • Jupyter Notebook: version 4.0.0 only; version 4.0.1 only; version 4.0.2 only; version 4.0.3 only; version 4.0.4 only

Published 2015-09-29. Last modified 2026-06-17.