Details
-
Bug
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
None
-
None
-
None
Description
The %md interpreter can be used to store XSS in notebooks. These cells are automatically loaded by the user when opening the notebook, so, no manual user interaction is needed.
Also, it doesn't matter if the cell has already a result or not.
%md
- foo <script>alert(String.fromCharCode(88,83,83))</script>