VendorsJupyterjupyterhuball versions
Vulnerabilities

Jupyter Jupyterhub

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2024-28233
XSS in JupyterHub via Self-XSS leveraged by Cookie Tossing
Published 2024-03-27 · Analyzed
8.1EPSS 0.003
CVE-2021-41247
incomplete logout in JupyterHub
Published 2021-11-04 · Modified
7.5EPSS 0.008
CVE-2024-41942
JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
Published 2024-08-08 · Analyzed
7.2EPSS 0.006
CVE-2019-10255
An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allows crafted links to the login page, which will redirect to a malicious site after successful login. Servers running on a base_url prefix are not affected.
Published 2019-03-28 · Modified
6.1EPSS 0.018
CVE-2026-33709
JupyterHub has an Open Redirect Vulnerability
Published 2026-04-03 · Analyzed
6.1EPSS 0.003
CVE-2026-40864
JupyterHub: Cross-origin form POSTs bypass XSRF
Published 2026-05-22 · Analyzed
5.4EPSS 0.002
CVE-2020-36191
JupyterHub 1.1.0 allows CSRF in the admin panel via a request that lacks an _xsrf field, as demonstrated by a /hub/api/user request (to add or remove a user account).
Published 2021-01-13 · Modified
4.5EPSS 0.005