GHSA-rch3-82jr-f9w9
HIGHCVE-2026-40171A stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook allows attackers to steal authentication tokens from users who open malicious notebook files and interact with elements that the attacker can make look indistinguishable from legitimate controls (single click interaction).
- Affected
- >=0, <4.5.7
- Fixed in
- not stated
- Weakness
- CWE-601
- Published
- 2026-04-30
- Source
- osv