jupyter-server vulnerabilities
CVEs whose affected-version data names the jupyter-server package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
12 CVEsRSS
CVE-2026-44727Medium· 5.4Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP
Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP
CVE-2026-5422Medium· 6.8Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path()
Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path()
CVE-2025-61669MediumJupyter Server has an open redirection vulnerability in `next` query parameter
Jupyter Server has an open redirection vulnerability in `next` query parameter
CVE-2026-40934Medium· 6.8Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart
Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart
CVE-2026-40110HighJupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`
Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`
CVE-2024-35178High· 7.5Jupyter server on Windows discloses Windows user password hash
Jupyter server on Windows discloses Windows user password hash
CVE-2023-49080Medium· 4.3jupyter-server errors include tracebacks with path information
jupyter-server errors include tracebacks with path information
CVE-2023-39968Medium· 6.1Open Redirect Vulnerability in jupyter-server
Open Redirect Vulnerability in jupyter-server
CVE-2023-40170Medium· 4.6cross-site inclusion (XSSI) of files in jupyter-server
cross-site inclusion (XSSI) of files in jupyter-server
CVE-2022-29241High· 7.1Jupyter server Token bruteforcing
Jupyter server Token bruteforcing
CVE-2020-26275Medium· 6.1Jupyter Server open redirect vulnerability
Jupyter Server open redirect vulnerability
CVE-2020-26232Medium· 4.1Open redirect in Jupyter Server
Open redirect in Jupyter Server