Notebook
Vendor:
First CVE: Sep 21, 2015 · Active for 10 years
17
Total CVEs
More Total CVEs than 93% of tracked products
2.1
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Notebook over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 21, 2015
10 years ago
Most Recent CVE
May 13, 2026
74 days ago
CVE Severity & Scoring
Notebook17 CVEs
76%
12%
12%
All CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (5.9%)
Network14 (82.4%)
Unknown2 (11.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (88.2%)
High0 (0.0%)
Unknown2 (11.8%)
User Interaction
None3 (17.6%)
Unknown2 (11.8%)
Required12 (70.6%)
Privileges Required
Low1 (5.9%)
High0 (0.0%)
None14 (82.4%)
Unknown2 (11.8%)
Top CVEs
Signals from CVEs in this product scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42557CRITICAL jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlis | May 13, 2026 | 9.6 | 37 | NO | NO |
CVE-2021-32798CRITICAL The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load. Jupyter Notebook uses a deprec | Aug 9, 2021 | 9.6 | 31 | NO | NO |
CVE-2022-24758HIGH The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized actors can access sensitive information from server logs. A | Mar 31, 2022 | 7.5 | 25 | NO | NO |
CVE-2018-8768HIGH In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by | Mar 18, 2018 | 7.8 | 25 | NO | NO |
CVE-2019-10255MEDIUM An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allows crafted links to the login pa | Mar 28, 2019 | 6.1 | 22 | NO | NO |
CVE-2018-19351MEDIUM Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconv | Nov 18, 2018 | 6.1 | 22 | NO | NO |
CVE-2019-10856MEDIUM In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists because of an incomplete fix for CVE-2019-10255. | Apr 4, 2019 | 6.1 | 21 | NO | NO |
CVE-2018-19352MEDIUM Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles certain URLs unsafely. | Nov 18, 2018 | 6.1 | 21 | NO | NO |
CVE-2024-22421MEDIUM JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious lin | Jan 19, 2024 | 6.5 | 20 | NO | NO |
CVE-2020-26215MEDIUM Jupyter Notebook before version 6.1.5 has an Open redirect vulnerability. A maliciously crafted link to a notebook server could redirect the browser to a different website. All not | Nov 18, 2020 | 6.1 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (17 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (17 CVEs).
Media Mentions
Signals from CVEs in this product scope (17 CVEs).
Top CNAs Publishing CVEs For Notebook
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.4.0 | 1 | 9.6 | 2.1% | 0 | 0 |
| 4.0.4 | 2 | 5.5 | 2.6% | 0 | 0 |
| 4.0.3 | 2 | 5.5 | 2.6% | 0 | 0 |
| 4.0.2 | 2 | 5.5 | 2.6% | 0 | 0 |
| 4.0.1 | 2 | 5.5 | 2.6% | 0 | 0 |
| 4.0.0 | 2 | 5.5 | 2.6% | 0 | 0 |