Skip to content

Consider updating MathJax to >=3 to avoid CVE-2023-39663 #353

@delsner

Description

@delsner

Description

Currently, nbclassic includes MathJax <=2.7.9. Any version <=3 of MathJax is vulnerable to a potential ReDoS attack (CVE-2023-39663, issue). While the vulnerability is not easily exploitable, it does pop up as a high severity CVE finding when scanning any environment that includes nbclassic.

Reproduce

Use a CVE scanner (e.g., grype) to scan an environment that includes nbclassic.

Expected behavior

No CVE findings for the most up-to-date version of nbclassic.

Context

  • Operating System and version: macOS (15.5)
  • Jupyter NbClassic version: 1.3.1

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions