VendorsJupyterjupyter_serverany version
Vulnerabilities

Jupyter Jupyter Server any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2026-44727
Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP
Published 2026-06-22 · Modified
9.3EPSS 0.004
CVE-2022-29241
Known or guessable hidden files may be accessed in Jupyter Server
Published 2022-06-14 · Modified
9.0EPSS 0.009
CVE-2026-35397
jupyter-server path traversal allows access to sibling directories sharing root_dir name prefix
Published 2026-05-05 · Modified
8.8EPSS 0.006
CVE-2026-6657
CORS Origin Validation Bypass in jupyter-server
Published 2026-06-03 · Analyzed
8.8EPSS 0.002
CVE-2026-40110
jupyter-server CORS origin validation bypass via unanchored regex in allow_origin_pat
Published 2026-05-05 · Modified
7.6EPSS 0.003
CVE-2026-40934
jupyter-server authentication cookies remain valid after password reset due to static cookie secret
Published 2026-05-05 · Analyzed
7.6EPSS 0.003
CVE-2022-24757
Sensitive Auth & Cookie data stored in Jupyter server logs
Published 2022-03-23 · Modified
7.5EPSS 0.013
CVE-2024-35178
Jupyter server on Windows discloses Windows user password hash
Published 2024-06-06 · Modified
7.5EPSS 0.007
CVE-2025-61669
jupyter_server next parameter open redirect can redirect users to external domains
Published 2026-05-05 · Analyzed
6.3EPSS 0.003
CVE-2020-26275
Open redirect vulnerability
Published 2020-12-21 · Modified
6.1EPSS 0.014
CVE-2023-39968
Open Redirect Vulnerability in jupyter-server
Published 2023-08-28 · Modified
6.1EPSS 0.007
CVE-2023-40170
cross-site inclusion (XSSI) of files in jupyter-server
Published 2023-08-28 · Modified
6.1EPSS 0.006
CVE-2020-26232
Open redirect in Jupyter Server
Published 2020-11-24 · Modified
5.5EPSS 0.010
CVE-2023-49080
Jupyter Server errors include tracebacks with path information
Published 2023-12-04 · Modified
4.3EPSS 0.008