VDB
Sign up
—

PYSEC-2022-249

Quick fix

PYSEC-2022-249 — nbconvert: upgrade to the fixed version with the command below.

pip install --upgrade 'nbconvert>=6.3.0a0'

Details

The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using nbconvert to generate an HTML version of a user-controllable notebook, it is possible to inject arbitrary HTML which may lead to cross-site scripting (XSS) vulnerabilities if these HTML notebooks are served by a web server (eg: nbviewer).

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/nbconvert
Introduced in: 0Fixed in: 6.3.0a0
Fixpip install --upgrade 'nbconvert>=6.3.0a0'

References