Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-c3mw-737p-c7g2
  • PyPI/jupyter-server
Jupyter Server: 5xx request logging leaks token-bearing Referer header values 3 days ago
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-3472
  • PyPI/jupyter-server
jupyter-server is vulnerable to CORS origin validation bypass when the `allow_origin_pat` configuration is used 23 Jul
  • No fix available
  • Severity - 6.1 (Medium)
PYSEC-2026-2532
  • PyPI/jupyter-server
Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path() 13 Jul
  • Fix available
  • Severity - 6.8 (Medium)
PYSEC-2026-2681
  • PyPI/notebook
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content 13 Jul
  • Fix available
  • Severity - 8.6 (High)
PYSEC-2026-2537
  • PyPI/jupyterlab
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content 13 Jul
  • Fix available
  • Severity - 8.6 (High)
PYSEC-2026-2538
  • PyPI/jupyterlab
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS 13 Jul
  • Fix available
  • Severity - 8.4 (High)
PYSEC-2026-2682
  • PyPI/notebook
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS 13 Jul
  • Fix available
  • Severity - 8.4 (High)
PYSEC-2026-2536
  • PyPI/jupyterlab
HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering 13 Jul
  • Fix available
  • Severity - 8.8 (High)
PYSEC-2026-2534
  • PyPI/jupyterlab
JupyterLab vulnerable to potential authentication and CSRF tokens leak 13 Jul
  • Fix available
  • Severity - 7.6 (High)
PYSEC-2026-2535
  • PyPI/jupyterlab
JupyterLab vulnerable to SXSS in Markdown Preview 13 Jul
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-2531
  • PyPI/jupyter-notebook
Improper Neutralization of Input During Web Page Generation in Jupyter Notebook 09 Jul
  • Fix available
  • Severity - 5.1 (Medium)
PYSEC-2026-1477
  • PyPI/jupyter-core
Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability 07 Jul
  • Fix available
  • Severity - 7.3 (High)
PYSEC-2026-1481
  • PyPI/notebook
HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering 07 Jul
  • Fix available
  • Severity - 8.8 (High)
PYSEC-2026-1479
  • PyPI/jupyter-scheduler
jupyter-scheduler's endpoint is missing authentication 07 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-1706
  • PyPI/notebook
JupyterLab vulnerable to potential authentication and CSRF tokens leak 07 Jul
  • Fix available
  • Severity - 7.6 (High)
PYSEC-2026-1707
  • PyPI/notebook
JupyterLab vulnerable to SXSS in Markdown Preview 07 Jul
  • Fix available
  • Severity - 6.5 (Medium)