Debian Package Tracker
Register | Log in
Subscribe

nbconvert

Choose email to subscribe with

general
  • source: nbconvert (main)
  • version: 7.17.1-2
  • maintainer: Debian Python Team (DMD)
  • uploaders: Gordon Ball [DMD] – Julien Puydt [DMD]
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 5.6.1-3
  • o-o-sec: 5.6.1-3+deb11u1
  • oldstable: 6.5.3-3
  • stable: 7.16.6-1+deb13u1
  • testing: 7.17.1-2
  • unstable: 7.17.1-2
versioned links
  • 5.6.1-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 5.6.1-3+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.5.3-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 7.16.6-1+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 7.17.1-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • jupyter-nbconvert
  • python-nbconvert-doc
  • python3-nbconvert
action needed
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2026-6658: A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows for Cross-site Scripting (XSS) via unsanitized `text/vnd.mermaid` output in HTML exports. The `data_mermaid` block in `share/templates/lab/base.html.j2` renders `text/vnd.mermaid` cell output directly into HTML without escaping, enabling attackers to inject arbitrary HTML/JavaScript by breaking out of the `<pre>` tag. This vulnerability impacts any server using nbconvert to render notebooks as HTML, allowing attackers to execute arbitrary JavaScript in the context of users viewing the HTML export.
Created: 2026-06-27 Last update: 2026-07-18 00:31
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-6658: A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows for Cross-site Scripting (XSS) via unsanitized `text/vnd.mermaid` output in HTML exports. The `data_mermaid` block in `share/templates/lab/base.html.j2` renders `text/vnd.mermaid` cell output directly into HTML without escaping, enabling attackers to inject arbitrary HTML/JavaScript by breaking out of the `<pre>` tag. This vulnerability impacts any server using nbconvert to render notebooks as HTML, allowing attackers to execute arbitrary JavaScript in the context of users viewing the HTML export.
Created: 2026-06-27 Last update: 2026-07-18 00:31
debian/patches: 2 patches with invalid metadata, 2 patches to forward upstream high

Among the 7 debian patches available in version 7.17.1-2 of the package, we noticed the following issues:

  • 2 patches with invalid metadata that ought to be fixed.
  • 2 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-06-21 07:30
Does not build reproducibly during testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2022-01-12 Last update: 2026-07-21 06:02
lintian reports 26 warnings normal
Lintian reports 26 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-04-27 Last update: 2026-04-27 14:01
1 low-priority security issue in trixie low

There is 1 open security issue in trixie.

1 issue left for the package maintainer to handle:
  • CVE-2026-6658: (needs triaging) A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows for Cross-site Scripting (XSS) via unsanitized `text/vnd.mermaid` output in HTML exports. The `data_mermaid` block in `share/templates/lab/base.html.j2` renders `text/vnd.mermaid` cell output directly into HTML without escaping, enabling attackers to inject arbitrary HTML/JavaScript by breaking out of the `<pre>` tag. This vulnerability impacts any server using nbconvert to render notebooks as HTML, allowing attackers to execute arbitrary JavaScript in the context of users viewing the HTML export.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-06-27 Last update: 2026-07-18 00:31
2 low-priority security issues in bookworm low

There are 2 open security issues in bookworm.

2 issues left for the package maintainer to handle:
  • CVE-2026-6658: (postponed; to be fixed through a stable update) A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows for Cross-site Scripting (XSS) via unsanitized `text/vnd.mermaid` output in HTML exports. The `data_mermaid` block in `share/templates/lab/base.html.j2` renders `text/vnd.mermaid` cell output directly into HTML without escaping, enabling attackers to inject arbitrary HTML/JavaScript by breaking out of the `<pre>` tag. This vulnerability impacts any server using nbconvert to render notebooks as HTML, allowing attackers to execute arbitrary JavaScript in the context of users viewing the HTML export.
  • CVE-2026-39378: (needs triaging) The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. In versions 6.5 through 7.17.0, when `HTMLExporter.embed_images=True`, nbconvert's markdown renderer allows arbitrary file read via path traversal in image references. A malicious notebook can exfiltrate sensitive files from the conversion host by embedding them as base64 data URIs in the output HTML. nbconvert 7.17.1 contains a fix. As a workaround, do not enable `HTMLExporter.embed_images`; it is not enabled by default.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-04-22 Last update: 2026-07-18 00:31
news
[rss feed]
  • [2026-07-04] Accepted nbconvert 7.16.6-1+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Adrian Bunk)
  • [2026-06-24] nbconvert 7.17.1-2 MIGRATED to testing (Debian testing watch)
  • [2026-06-20] Accepted nbconvert 7.17.1-2 (source) into unstable (Alexandre Detiste)
  • [2026-04-30] nbconvert 7.17.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-26] Accepted nbconvert 7.17.1-1 (source) into unstable (Colin Watson)
  • [2026-02-20] nbconvert 7.17.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-10] Accepted nbconvert 7.17.0-1 (source) into unstable (Gordon Ball)
  • [2025-02-12] nbconvert 7.16.6-1 MIGRATED to testing (Debian testing watch)
  • [2025-02-09] Accepted nbconvert 7.16.6-1 (source) into unstable (Colin Watson)
  • [2025-01-08] nbconvert 7.16.5-1 MIGRATED to testing (Debian testing watch)
  • [2025-01-02] Accepted nbconvert 7.16.5-1 (source) into unstable (Colin Watson)
  • [2024-09-27] nbconvert 7.16.4-2 MIGRATED to testing (Debian testing watch)
  • [2024-09-25] Accepted nbconvert 7.16.4-2 (source) into unstable (Colin Watson)
  • [2024-09-02] Accepted nbconvert 5.6.1-3+deb11u1 (source) into oldstable-security (Guilhem Moulin)
  • [2024-06-24] nbconvert 7.16.4-1 MIGRATED to testing (Debian testing watch)
  • [2024-06-02] Accepted nbconvert 7.16.4-1 (source) into unstable (Colin Watson)
  • [2024-04-20] nbconvert 6.5.3-5 MIGRATED to testing (Debian testing watch)
  • [2024-04-14] Accepted nbconvert 6.5.3-5 (source) into unstable (Colin Watson)
  • [2023-07-23] nbconvert 6.5.3-4 MIGRATED to testing (Debian testing watch)
  • [2023-07-21] Accepted nbconvert 6.5.3-4 (source) into unstable (Benjamin Drung)
  • [2023-06-03] Accepted nbconvert 5.4-2+deb10u1 (source) into oldstable (Guilhem Moulin)
  • [2023-01-21] nbconvert 6.5.3-3 MIGRATED to testing (Debian testing watch)
  • [2023-01-18] Accepted nbconvert 6.5.3-3 (source) into unstable (Jochen Sprickerhof)
  • [2022-11-27] nbconvert 6.5.3-2 MIGRATED to testing (Debian testing watch)
  • [2022-11-24] Accepted nbconvert 6.5.3-2 (source) into unstable (Gordon Ball)
  • [2022-11-07] nbconvert 6.5.3-1.1 MIGRATED to testing (Debian testing watch)
  • [2022-11-07] nbconvert 6.5.3-1.1 MIGRATED to testing (Debian testing watch)
  • [2022-11-04] Accepted nbconvert 6.5.3-1.1 (source) into unstable (Paul Gevers)
  • [2022-09-07] Accepted nbconvert 6.5.3-1 (source) into unstable (Julien Puydt)
  • [2022-08-10] Accepted nbconvert 6.5.1-1 (source) into unstable (Julien Puydt)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 0
  • M&W: 1
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 26)
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 7.17.1-2

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing