CVE-2021-32862 describes a cross-site scripting (XSS) vulnerability in nbconvert, affecting Debian Linux and Jupyter nbconvert. This flaw allows an attacker to inject arbitrary HTML when converting user-controlled notebooks to HTML, potentially leading to XSS if these generated files are hosted on a web server. With a CVSS score of 5.4 (Medium), exploitation requires user interaction and low privileges, resulting in low impact to confidentiality and integrity. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.2.0CPE matchmatch criteria | cpe:2.3:a:jupyter:nbconvert:*:*:*:*:*:python:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.