Cross-site scripting in Jupyter Notebook - CVE-2026-40171
Published: May 4, 2026
Jupyter Notebook
Detailed vulnerability description
The vulnerability allows a remote user to steal authentication tokens and execute arbitrary code.
The vulnerability exists due to cross-site scripting in the help extension command linker functionality when rendering malicious notebook content. A remote privileged user can craft a malicious notebook file and induce a single click on attacker-controlled elements to steal authentication tokens and execute arbitrary code.
User interaction is required to open a malicious notebook file and click an element made to appear indistinguishable from a legitimate control.