CVE-2024-35178High· 7.5▾ TwilightJupyter server on Windows discloses Windows user password hash
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.7%
Jupyter Server on Windows has a vulnerability that lets unauthenticated attackers leak the NTLMv2 password hash of the Windows user running the Jupyter server. An attacker can crack this password to gain access to the Windows machine hosting the Jupyter server, or access other network-accessible machines or 3rd party services using that credential. Or an attacker perform an NTLM relay attack without cracking the credential to gain access to other network-accessible machines.
jupyter-server < 2.14.1Upgrade to a patched release:
jupyter-server 2.14.1Connected by shared product, vendor, weakness, or advisory.
CVE-2023-39968Medium· 6.1Open Redirect Vulnerability in jupyter-server
CVE-2025-61669MediumJupyter Server has an open redirection vulnerability in `next` query parameter
CVE-2022-29241High· 7.1Jupyter server Token bruteforcing
CVE-2023-49080Medium· 4.3jupyter-server errors include tracebacks with path information
CVE-2020-26232Medium· 4.1Open redirect in Jupyter Server
CVE-2023-40170Medium· 4.6cross-site inclusion (XSSI) of files in jupyter-server