Notebook

Vendor:

First CVE: Sep 21, 2015 · Active for 10 years

17
Total CVEs
More Total CVEs than 93% of tracked products
2.1
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Notebook over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 21, 2015
10 years ago
Most Recent CVE
May 13, 2026
74 days ago

CVE Severity & Scoring

Notebook17 CVEs
All CVEs352,719 CVEs
MediumHighCritical
Attack Vector
Local1 (5.9%)
Network14 (82.4%)
Unknown2 (11.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (88.2%)
High0 (0.0%)
Unknown2 (11.8%)
User Interaction
None3 (17.6%)
Unknown2 (11.8%)
Required12 (70.6%)
Privileges Required
Low1 (5.9%)
High0 (0.0%)
None14 (82.4%)
Unknown2 (11.8%)

Top CVEs

Signals from CVEs in this product scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlis
May 13, 20269.637NONO
The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load. Jupyter Notebook uses a deprec
Aug 9, 20219.631NONO
The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized actors can access sensitive information from server logs. A
Mar 31, 20227.525NONO
In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by
Mar 18, 20187.825NONO
An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allows crafted links to the login pa
Mar 28, 20196.122NONO
Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconv
Nov 18, 20186.122NONO
In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists because of an incomplete fix for CVE-2019-10255.
Apr 4, 20196.121NONO
Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles certain URLs unsafely.
Nov 18, 20186.121NONO
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious lin
Jan 19, 20246.520NONO
Jupyter Notebook before version 6.1.5 has an Open redirect vulnerability. A maliciously crafted link to a notebook server could redirect the browser to a different website. All not
Nov 18, 20206.120NONO

Exploit Exposure

Signals from CVEs in this product scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (17 CVEs).

Media Mentions

Signals from CVEs in this product scope (17 CVEs).

Top CNAs Publishing CVEs For Notebook

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.4.019.62.1%00
4.0.425.52.6%00
4.0.325.52.6%00
4.0.225.52.6%00
4.0.125.52.6%00
4.0.025.52.6%00