{"id":"GHSA-gj55-2xf9-67rq","summary":"HTML injection in JupyterLite leading to DOM Clobbering","details":"### Impact\n\nThe vulnerability depends on user interaction by opening a malicious notebook with Markdown cells, or Markdown file using JupyterLab preview feature.\n\nA malicious user can access any data accessible from JupyterLite and perform arbitrary actions in JupyterLite environment.\n\n### Patches\n\nJupyterLite 0.4.1 was patched.\n\n### Workarounds\n\nThere is no workaround for the underlying DOM Clobbering susceptibility. However, select plugins can be disabled on deployments which cannot update in a timely fashion to minimise the risk. These are:\n- `@jupyterlab/mathjax-extension:plugin` - users will loose ability to preview mathematical equations \n- `@jupyterlab/markdownviewer-extension:plugin` - users will loose ability to open Markdown previews\n- `@jupyterlab/mathjax2-extension:plugin` (if installed with optional `jupyterlab-mathjax2` package) - an older version of the mathjax plugin for JupyterLab 4.x\n\nTo disable these extensions populate the `disabledExtensions` key in `jupyter-config-data` stanza of `jupyter-lite.json` as documented on https://jupyterlite.readthedocs.io/en/stable/howto/configure/config_files.html#jupyter-lite-json\n\n```json\n{\n  \"jupyter-lite-schema-version\": 0,\n  \"jupyter-config-data\": {\n    \"appName\": \"My JupyterLite App\",\n    \"disabledExtensions\": [\n      \"@jupyterlab/markdownviewer-extension:plugin\",\n      \"@jupyterlab/mathjax-extension:plugin\",\n      \"@jupyterlab/mathjax2-extension:plugin\"\n    ]\n  }\n}\n```\n\nTo confirm that the plugins were disabled manual inspection of the built page is required.\n\n### References\n\nUpstream advisory: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-9q39-rmj3-p4r2\n\n### Notes\n\nThis change has a potential to break rendering of some markdown. There is a setting in Sanitizer which allows to revert to the previous sanitizer settings (`allowNamedProperties`).","modified":"2024-11-28T05:39:07.411996Z","published":"2024-09-06T19:51:19Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-09-06T19:51:19Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-9q39-rmj3-p4r2"},{"type":"WEB","url":"https://github.com/jupyterlite/jupyterlite/security/advisories/GHSA-gj55-2xf9-67rq"},{"type":"PACKAGE","url":"https://github.com/jupyterlite/jupyterlite"}],"affected":[{"package":{"name":"jupyterlite-core","ecosystem":"PyPI","purl":"pkg:pypi/jupyterlite-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.4.1"}]}],"versions":["0.0.0a0","0.1.0","0.1.0a0","0.1.0a1","0.1.0b19","0.1.0b20","0.1.0b21","0.1.0b22","0.1.0rc0","0.1.1","0.1.2","0.1.3","0.2.0","0.2.0a0","0.2.0a1","0.2.0a2","0.2.0a3","0.2.0a4","0.2.0b0","0.2.0b1","0.2.0rc0","0.2.0rc1","0.2.1","0.2.2","0.2.3","0.3.0","0.3.0a0","0.3.0a1","0.3.0b0","0.3.0rc0","0.3.0rc1","0.4.0","0.4.0a0","0.4.0a1","0.4.0a2","0.4.0a3","0.4.0b0","0.4.0b1","0.4.0rc0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-gj55-2xf9-67rq/GHSA-gj55-2xf9-67rq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N"}]}