Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2021-41134

8.7 · HIGH
Published Nov 3, 2021 jupyter CWE-79 EPSS 0.70% (51th pctl)

Overview

CVE-2021-41134 is a high-severity vulnerability affecting jupyter nbdime. It was published on November 3, 2021 and has a CVSS 3.1 base score of 8.7 (HIGH).

This vulnerability has a CVSS 3.1 base score of 8.7, rated HIGH. It can be exploited remotely over the network. Some level of privileges is required for exploitation.

Technical Description

nbdime provides tools for diffing and merging of Jupyter Notebooks. In affected versions a stored cross-site scripting (XSS) issue exists within the Jupyter-owned nbdime project. It appears that when reading the file name and path from disk, the extension does not sanitize the string it constructs before returning it to be displayed. The diffNotebookCheckpoint function within nbdime causes this issue. When attempting to display the name of the local notebook (diffNotebookCheckpoint), nbdime appears to simply append .ipynb to the name of the input file. The NbdimeWidget is then created, and the base string is passed through to the request API function. From there, the frontend simply renders the HTML tag and anything along with it. Users are advised to patch to the most recent version of the affected product.

Remediation

Check the references section for vendor advisories and patches from jupyter. Update nbdime to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
jupyter nbdime >= 1.0.0, < 1.1.1 Affected
jupyter nbdime-jupyterlab >= 1.0.0, < 1.0.1 Affected

Frequently Asked Questions

What is CVE-2021-41134?

CVE-2021-41134 is a high-severity vulnerability affecting jupyter nbdime. It was published on November 3, 2021 and has a CVSS 3.1 base score of 8.7 (HIGH).

How severe is CVE-2021-41134?

This vulnerability has a CVSS 3.1 base score of 8.7, rated HIGH. It can be exploited remotely over the network. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2021-41134?

Check the references section for vendor advisories and patches from jupyter. Update nbdime to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2021-41134?

CyberStrike's AI-powered security agents can automatically detect CVE-2021-41134 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.