—
PYSEC-2022-249
Quick fix
PYSEC-2022-249 — nbconvert: upgrade to the fixed version with the command below.
pip install --upgrade 'nbconvert>=6.3.0a0'Details
The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using nbconvert to generate an HTML version of a user-controllable notebook, it is possible to inject arbitrary HTML which may lead to cross-site scripting (XSS) vulnerabilities if these HTML notebooks are served by a web server (eg: nbviewer).
Are you affected?
Enter the version of the package you're using.