Database/AI/ML frameworks & serving
Jupyter Notebook (untrusted notebooks): Untrusted notebook executes JavaScript in the user's session on open
CVSS 10.0CVE-2021-32798AI/ML frameworks & servingcurated
Impact
Untrusted notebook executes JavaScript in the user's session on open
Who can reach it
Customer-supplied .ipynb opened by another user or an operator
What to do
Upgrade. Notebook files shared between tenants are active content
References
Related entries
- MLflow: Absolute path traversal prior to 2.5.0CVE-2023-3765 · MLflowCritical
- TorchServe: Unauthenticated SSRFCVE-2023-43654 · TorchServeCritical
- BentoML: Insecure deserializationCVE-2024-2912 · BentoMLCritical
- llama.cpp (RPC backend): Unsafe `data` pointer in `rpc_tensor`CVE-2024-42479 · llama.cpp (RPC backend)Critical
- MLflow (`extract_archive_to_dir`): Path traversal in the dbconnect artifact cacheCVE-2025-15036 · MLflow (`extract_archive_to_dir`)Critical
- vLLM (Mooncake ZMQ/TCP): Unsafe deserialization exposed on all interfacesCVE-2025-32444 · vLLM (Mooncake ZMQ/TCP)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.