{"id":"CVE-2020-26275","aliases":["GHSA-9f66-54xg-pc2c","PYSEC-2020-346","PYSEC-2020-50"],"title":"Jupyter Server open redirect vulnerability","summary":"Jupyter Server open redirect vulnerability","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","vendor":"jupyter-server","product":"jupyter-server","ecosystem":"pip","affected":["jupyter-server < 1.1.1"],"patched":["jupyter-server 1.1.1"],"published":"2020-12-21","updated":"2026-07-08","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-9f66-54xg-pc2c","references":[{"url":"https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-9f66-54xg-pc2c"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-26275"},{"url":"https://github.com/jupyter-server/jupyter_server/commit/85e4abccf6ea9321d29153f73b0bd72ccb3a6bca"},{"url":"https://advisory.checkmarx.net/advisory/CX-2020-4291"},{"url":"https://github.com/jupyter-server/jupyter_server"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/jupyter-server/PYSEC-2020-346.yaml"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/jupyter-server/PYSEC-2020-50.yaml"},{"url":"https://pypi.org/project/jupyter-server"}],"tags":["osv","pip"],"epss":0.01379,"epssPercentile":0.70897,"ingestedAt":"2026-07-08T18:25:47.839Z","slug":"CVE-2020-26275","body":"## Overview\n\n### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\nOpen redirect vulnerability - a maliciously crafted link to a jupyter server could redirect the browser to a different website.\n\nAll jupyter servers running without a base_url prefix are technically affected, however, these maliciously crafted links can only be reasonably made for known jupyter server hosts. A link to your jupyter server may *appear* safe, but ultimately redirect to a spoofed server on the public internet. This same vulnerability was patched in upstream notebook v5.7.8.\n\n### Patches\n\n_Has the problem been patched? What versions should users upgrade to?_\n\nPatched in jupyter_server 1.1.1. If upgrade is not available, a workaround can be to run your server on a url prefix:\n\n```\njupyter server --ServerApp.base_url=/jupyter/\n```\n\n### References\n\n[OWASP page on open redirects](https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html)\n\n### For more information\n\nIf you have any questions or comments about this advisory, or vulnerabilities to report, please email our security list [security@ipython.org](mailto:security@ipython.org).\n\nCredit: Yaniv Nizry from CxSCA group at Checkmarx\n\n## Affected packages\n\n- `jupyter-server < 1.1.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `jupyter-server 1.1.1`","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}