Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:pypi/nbconvert

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

A path traversal vulnerability exists in jupyter nbconvert versions 6.5 through 7.17.0 when the HTMLExporter.embed_images option is enabled. This flaw allows a malicious notebook to read arbitrary files from the host system by embedding them as base64 data URIs in the output HTML. The vulnerability is fixed in version 7.17.1. By default, HTMLExporter.

Join the discussion

A path traversal vulnerability exists in jupyter nbconvert versions 6.5 through 7.17.0. The vulnerability arises from the ExtractAttachmentsPreprocessor component, which does not sanitize attachment filenames, allowing crafted filenames to write files outside the intended output directory. This enables an attacker to control the destination path and file extension of arbitrary files written to the filesystem. Version 7.17.1 includes a patch addressing this issue. The vulnerability has a medium severity with a CVSS score of 6.

Join the discussion

The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. Versions of nbconvert up to and including 7.16.6 on Windows have a vulnerability in which converting a notebook containing SVG output to a PDF results in unauthorized code execution. Specifically, a third party can create a `inkscape.bat` file that defines a Windows batch script, capable of arbitrary code execution. When a user runs `jupyter nbconvert --to pdf` on a notebook containing SVG output to a PDF on a Windows platform from this directory, the `inkscape.bat` file is run unexpectedly. This issue has been patched in version 7.17.0.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Package: pkg:pypi/nbconvert
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses