-
Couldn't load subscription status.
- Fork 65
Open
Labels
bugSomething isn't workingSomething isn't working
Description
Description
Currently, nbclassic includes MathJax <=2.7.9. Any version <=3 of MathJax is vulnerable to a potential ReDoS attack (CVE-2023-39663, issue). While the vulnerability is not easily exploitable, it does pop up as a high severity CVE finding when scanning any environment that includes nbclassic.
Reproduce
Use a CVE scanner (e.g., grype) to scan an environment that includes nbclassic.
Expected behavior
No CVE findings for the most up-to-date version of nbclassic.
Context
- Operating System and version: macOS (15.5)
- Jupyter NbClassic version: 1.3.1
RRosio and ajalon1
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't working