CVE-2015-6938

medium
Published 2022-05-14 · Modified 2023-11-08
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2
4.3
VIR risk
4.3

Description

Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via a folder name. NOTE: this was originally reported as a cross-site request forgery (CSRF) vulnerability, but this may be inaccurate.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-6938

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/jupyter/notebook/commit/dd9876381f0ef09873d8c5f6f2063269172331e3

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://seclists.org/oss-sec/2015/q3/544

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2.4.1-1
debian debianbullseyefixed2.4.1-1
debian debianforkyfixed2.4.1-1
debian debiansidfixed2.4.1-1
debian debiantrixiefixed2.4.1-1
suse suse13.1affected
suse suse13.2affected
fedora fedora21affected
fedora fedora22affected
fedora fedora23affected

Package impact

EcosystemPackageVulnerableFixed
python PyPInotebook>=4.0.0,<4.0.54.0.5
python PyPIipython<3.2.23.2.2
python PyPInotebook<dd9876381f0ef09873d8c5f6f2063269172331e3||>=4.0.0,<4.0.535f32dd2da804d108a3a3585b69ec3295b2677ed
python PyPIipython<3ab41641cf6fce3860c73d5cf4645aa12e1e5892||<3.2.23ab41641cf6fce3860c73d5cf4645aa12e1e5892

Application impact

VendorProductVersionsFixed
jupyternotebook4.0.0
jupyternotebook4.0.1
jupyternotebook4.0.2
jupyternotebook4.0.3
jupyternotebook4.0.4
ipythonnotebook{"endIncluding":"3.2.1"}

References

CWEs

CWE-79

Verify integrity in audit chain (admin only). AS-IS.