Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting jupyter.
- CVE-2026-44182Jupyter Enterprise Gateway Has Kubernetes Manifest Injection via Jinja2 Template Rendering10.0
- CVE-2026-44181Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Execution10.0
- CVE-2026-44180Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids can be Bypassed9.8
- CVE-2026-54528jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories7.1
- CVE-2026-54527JupyterLab Git: Stored XSS leading to RCE9.0
- CVE-2026-6658Cross-site Scripting (XSS) in jupyter/nbconvert5.4
- CVE-2026-44727Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP5.4
- CVE-2026-6657CORS Origin Validation Bypass in jupyter-server8.8
- CVE-2026-5422Path Traversal in jupyter/jupyter8.1
- CVE-2026-40864JupyterHub: Cross-origin form POSTs bypass XSRF5.4
- CVE-2026-42266JupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (malicious) extensions install via POST request.8.8
- CVE-2026-42557jupyterlab: Command linker attributes in HTML enable one-click command execution from untrusted content9.6
- CVE-2026-40934jupyter-server authentication cookies remain valid after password reset due to static cookie secret6.8
- CVE-2026-40110jupyter-server CORS origin validation bypass via unanchored regex in allow_origin_pat7.3
- CVE-2026-35397jupyter-server path traversal allows access to sibling directories sharing root_dir name prefix8.8