CVE-2018-8768: Jupyter Notebook

High severity, CVSS 7.8. EPSS: 1.1% chance of exploitation in the next 30 days.

In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by jQuery after sanitization, making it dangerous.

Affected products

  • Jupyter Notebook: before 5.4.1 (fixed in 5.4.1)

Published 2018-03-18. Last modified 2026-06-17.