---
id: CVE-2026-5422
aliases:
  - GHSA-gf7q-q4j7-hp7c
title: >-
  Jupyter Server vulnerable to Path Traversal via incorrect root directory
  boundary check in _get_os_path() 
summary: >-
  Jupyter Server vulnerable to Path Traversal via incorrect root directory
  boundary check in _get_os_path() 
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'
vendor: jupyter-server
product: jupyter-server
ecosystem: pip
affected:
  - jupyter-server < 2.18.2
patched:
  - jupyter-server 2.18.2
published: '2026-06-02'
updated: '2026-07-09'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-gf7q-q4j7-hp7c'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-5422'
  - url: 'https://github.com/jupyter-server/jupyter_server'
  - url: 'https://huntr.com/bounties/24a36953-6490-466f-8cb2-a90d1ca56e0f'
  - url: >-
      http://github.com/jupyter-server/jupyter_server/commit/0d829f2c35a481c3b24ecbe1e25a6f79954e88f2
tags:
  - osv
  - pip
epss: 0.00549
epssPercentile: 0.43583
ingestedAt: '2026-07-10T13:49:10.786Z'
---

## Overview

A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check in the _get_os_path() function within jupyter_server/services/contents/fileio.py. The check uses startswith(root) without appending a trailing path separator, allowing sibling directories with names starting with the same prefix as root_dir to bypass the check. Additionally, the to_os_path() function in utils.py does not strip ".." from path parts, enabling traversal sequences to bypass the vulnerable check. This vulnerability can lead to unauthorized read/write access to files in sibling directories, potentially exposing sensitive data in shared hosting environments.

## Affected packages

- `jupyter-server < 2.18.2`

## Remediation

Upgrade to a patched release:

- `jupyter-server 2.18.2`
