Loading
The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using nbconvert to generate an HTML version of a user-controllable notebook, it is possible to inject arbitrary HTML which may lead to cross-site scripting (XSS) vulnerabilities if these HTML notebooks are served by a web server (eg: nbviewer).
Use CWE-79, Jupyter vendor hub and Nbconvert product page to widen CVE-2021-32862 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-53000, CVE-2026-39378 and CVE-2026-39377 for nearby disclosures in the same product family.