REDHAT-BUG-2491516: XSS
Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyterserver render user-authored notebook HTML under the Jupyter origin without a sandbox directive in their Content-Security-Policy. Combined with nbconvert.HTMLExporter's default non-sanitizing behavior, a notebook carrying an HTML payload in a displaydata output triggers stored XSS with cookie access, full /api/ authority, and kernel RCE. This vulnerability is fixed in 2.20.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Jupyter Serverto a version that resolves this vulnerability.Fixed in 2.20
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2491516?
The severity of REDHAT-BUG-2491516 is high with a risk score of 7.
What is REDHAT-BUG-2491516 about?
REDHAT-BUG-2491516 describes a security vulnerability in Jupyter Server that allows XSS attacks due to insufficient Content-Security-Policy in nbconvert HTTP handlers.
How do I fix REDHAT-BUG-2491516?
To fix REDHAT-BUG-2491516, upgrade Jupyter Server to version 2.20 or later where the vulnerability has been addressed.
What impact does REDHAT-BUG-2491516 have?
The impact of REDHAT-BUG-2491516 includes potential cross-site scripting (XSS) attacks that could compromise user sessions.
When was REDHAT-BUG-2491516 published?
REDHAT-BUG-2491516 was published on June 22, 2026.