CVE 2018-19352
Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/
See the
CVE page on Mitre.org
for more details.
Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/