You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Currently, nbclassic includes MathJax <=2.7.9. Any version <=3 of MathJax is vulnerable to a potential ReDoS attack (CVE-2023-39663, issue). While the vulnerability is not easily exploitable, it does pop up as a high severity CVE finding when scanning any environment that includes nbclassic.
Reproduce
Use a CVE scanner (e.g., grype) to scan an environment that includes nbclassic.
Expected behavior
No CVE findings for the most up-to-date version of nbclassic.