Notebook
24 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Notebook, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Notebook CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 2 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 24 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High5
- Medium16
Latest CVEs
The 15 most recently published vulnerabilities affecting Notebook.
- CVE-2026-42557jupyterlab: Command linker attributes in HTML enable one-click command execution from untrusted content9.6
- CVE-2026-40171Jupyter Notebook and JupyterLab token theft via stored XSS in help command linker—
- CVE-2024-43805HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering7.6
- CVE-2024-22420Stored cross site scripting in Markdown Preview in JupyterLab6.5
- CVE-2024-22421Potential authentication and CSRF tokens leak in JupyterLab7.6
- CVE-2022-3746A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormall...6.7
- CVE-2022-3745A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to view incoming and returned data from SMI.4.4
- CVE-2022-3744A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-code...6.7
- CVE-2022-3743A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges under certain conditions the ability to enu...4.4
- CVE-2022-3742A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to execute arbitrary code due to improper b...6.7
- CVE-2022-29238Forced Browsing in Jupyter Notebook4.3
- CVE-2022-24758Insertion of Sensitive Information into Log File affects Jupyter Notebook7.5
- CVE-2021-32798Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in notebook10.0
- CVE-2021-32797JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>7.4
- CVE-2020-26215Open redirect in Jupyter Notebook4.4
Product grouping is registry-driven, with AI assist and human review. How it works