by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
29 packages
- rednotebook
- wolfram-notebook
- python312Packages.notebook-shim
- python313Packages.notebook-shim
- python314Packages.notebook-shim
- python312Packages.jupyterlab-vim
- python312Packages.jupyterlab-lsp
- python312Packages.jupyterlab-git
- python313Packages.jupyterlab-git
- python313Packages.jupyterlab-lsp
- python313Packages.jupyterlab-vim
- python314Packages.jupyterlab-git
- python314Packages.jupyterlab-lsp
- python314Packages.jupyterlab-vim
- python312Packages.pytest-notebook
- python313Packages.pytest-notebook
- python314Packages.pytest-notebook
- python312Packages.jupyterlab-server
- python313Packages.jupyterlab-server
- python314Packages.jupyterlab-server
- python312Packages.jupyterlab-widgets
- python313Packages.jupyterlab-widgets
- python314Packages.jupyterlab-widgets
- python312Packages.jupyterlab-pygments
- python313Packages.jupyterlab-pygments
- python314Packages.jupyterlab-pygments
- python312Packages.jupyterlab-execute-time
- python313Packages.jupyterlab-execute-time
- python314Packages.jupyterlab-execute-time
- @LeSuisse accepted
- @LeSuisse published on GitHub
Jupyter Notebook and JupyterLab token theft via stored XSS in help command linker
In Jupyter Notebook versions 7.0.0 through 7.5.5, JupyterLab versions 4.5.6 and earlier, and the corresponding @jupyter-notebook/help-extension and @jupyterlab/help-extension packages before 7.5.6 and 4.5.7, a stored cross-site scripting issue in the help command linker can be chained with attacker-controlled notebook content to steal authentication tokens with a single click. An attacker can craft a malicious notebook file containing elements that appear indistinguishable from legitimate controls and trigger execution when a user interacts with them. Successful exploitation allows theft of the user's authentication token and complete takeover of the Jupyter session through the REST API, including reading files, creating or modifying files, accessing kernels to execute arbitrary code, and creating terminals for shell access. This issue has been fixed in Notebook 7.5.6, JupyterLab 4.5.7, @jupyter-notebook/help-extension 7.5.6, and @jupyterlab/help-extension 4.5.7. As a workaround, disable the affected help extensions or set allowCommandLinker to false in the sanitizer configuration.
References
-
https://github.com/jupyter/notebook/security/advisories/GHSA-rch3-82jr-f9w9 x_refsource_CONFIRM
Affected products
- ==>=7.0.0, <= 7.5.5
- ==<= 4.5.6
- ==<=4.5.6
- ==>=7.0.0,<= 7.5.5
Matching in nixpkgs
pkgs.python312Packages.notebook
Web-based notebook environment for interactive computing
pkgs.python313Packages.notebook
Web-based notebook environment for interactive computing
pkgs.python314Packages.notebook
Web-based notebook environment for interactive computing
pkgs.python312Packages.jupyterlab
Jupyter lab environment notebook server extension
pkgs.python313Packages.jupyterlab
Jupyter lab environment notebook server extension
pkgs.python314Packages.jupyterlab
Jupyter lab environment notebook server extension
Ignored packages (29)
pkgs.rednotebook
Modern journal that includes a calendar navigation, customizable templates, export functionality and word clouds
pkgs.wolfram-notebook
None
pkgs.python312Packages.notebook-shim
Switch frontends to Jupyter Server
pkgs.python313Packages.notebook-shim
Switch frontends to Jupyter Server
pkgs.python314Packages.notebook-shim
Switch frontends to Jupyter Server
pkgs.python312Packages.jupyterlab-git
Jupyter lab extension for version control with Git
pkgs.python312Packages.jupyterlab-lsp
Language Server Protocol integration for Jupyter(Lab)
pkgs.python312Packages.jupyterlab-vim
Vim notebook cell bindings for JupyterLab
pkgs.python313Packages.jupyterlab-git
Jupyter lab extension for version control with Git
pkgs.python313Packages.jupyterlab-lsp
Language Server Protocol integration for Jupyter(Lab)
pkgs.python313Packages.jupyterlab-vim
Vim notebook cell bindings for JupyterLab
pkgs.python314Packages.jupyterlab-git
Jupyter lab extension for version control with Git
pkgs.python314Packages.jupyterlab-lsp
Language Server Protocol integration for Jupyter(Lab)
pkgs.python314Packages.jupyterlab-vim
Vim notebook cell bindings for JupyterLab
pkgs.python312Packages.pytest-notebook
Pytest plugin for regression testing and regenerating Jupyter Notebooks
pkgs.python313Packages.pytest-notebook
Pytest plugin for regression testing and regenerating Jupyter Notebooks
pkgs.python314Packages.pytest-notebook
Pytest plugin for regression testing and regenerating Jupyter Notebooks
pkgs.python312Packages.jupyterlab-server
Set of server components for JupyterLab and JupyterLab like applications
pkgs.python313Packages.jupyterlab-server
Set of server components for JupyterLab and JupyterLab like applications
pkgs.python314Packages.jupyterlab-server
Set of server components for JupyterLab and JupyterLab like applications
pkgs.python312Packages.jupyterlab-pygments
Jupyterlab syntax coloring theme for pygments
pkgs.python313Packages.jupyterlab-pygments
Jupyterlab syntax coloring theme for pygments
pkgs.python314Packages.jupyterlab-pygments
Jupyterlab syntax coloring theme for pygments
pkgs.python312Packages.jupyterlab-execute-time
JupyterLab extension for displaying cell timings
pkgs.python313Packages.jupyterlab-execute-time
JupyterLab extension for displaying cell timings
pkgs.python314Packages.jupyterlab-execute-time
JupyterLab extension for displaying cell timings
Package maintainers
-
@GaetanLepage Gaetan Lepage <gaetan@glepage.com>
-
@thomasjm Tom McLaughlin <tom@codedown.io>
-
@natsukium Tomoya Otabi <nixpkgs@natsukium.com>