Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-86049High· 7.1Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jupyter_server/log.py copies the Referer header into a JSON header block without applying the token scrubbing used for t…
CVE-2026-44727Medium· 5.4Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP
CVE-2026-5422Medium· 6.8Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path()
CVE-2025-61669MediumJupyter Server has an open redirection vulnerability in `next` query parameter
CVE-2026-40934Medium· 6.8Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart
CVE-2026-40110HighJupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`
CVE-2024-35178High· 7.5Jupyter server on Windows discloses Windows user password hash
CVE-2023-49080Medium· 4.3jupyter-server errors include tracebacks with path information
CVE-2023-39968Medium· 6.1Open Redirect Vulnerability in jupyter-server
CVE-2023-40170Medium· 4.6cross-site inclusion (XSSI) of files in jupyter-server
CVE-2022-29241High· 7.1Jupyter server Token bruteforcing
CVE-2020-26275Medium· 6.1Jupyter Server open redirect vulnerability
CVE-2020-26232Medium· 4.1Open redirect in Jupyter Server
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.