CVE-2021-32797: high-severity vulnerability in jupyterlab
JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.4epss 2.7%
exploitation probability
2.7%top 15% of all CVEs
observed exploitation
nono source reports it
JupyterLab is a user interface for Project Jupyter which will eventually replace the classic Jupyter Notebook. In affected versions untrusted notebook can execute code on load. In particular JupyterLab doesn’t sanitize the action attribute of html `<form>`. Using this it is possible to trigger the form validation outside of the form itself. This is a remote code execution, but requires user action to open a notebook.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Affected products
jupyterlab · jupyterlabRelated CVEs — jupyterlab
In the same product, most dangerous first.
CVE-2026-42266HIGHJupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (malicious) extensions install via POST request.EPSS 0.9%CVE-2026-73417HIGHJupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)EPSS 0.7%CVE-2026-73415HIGHjupyterlab: Image viewer in JupyterLab allows XSS when opening malicious image in new browser tabEPSS 0.7%CVE-2026-42557HIGHjupyterlab: Command linker attributes in HTML enable one-click command execution from untrusted contentEPSS 0.7%CVE-2024-22421HIGHPotential authentication and CSRF tokens leak in JupyterLabEPSS 0.7%CVE-2026-73416MEDIUMjupyterlab: PyPI extension blocklist package-name canonicalization bypassEPSS 0.7%