Jupyter Server是Jupyter组织的一款用于为Jupyter Web应用提供后端服务的应用软件。 Jupyter Server 2.17.0及之前版本存在输入验证错误漏洞,该漏洞源于登录流程中next查询参数验证不足,可能导致重定向到任意外部域,攻击者可通过特制登录URL将用户重定向到恶意站点并促进钓鱼攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jupyter-server | jupyter_server | <= 2.17.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jupyter-server | jupyter_server | <= 2.17.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-35397 | 7.6 HIGH | jupyter-server path traversal allows access to sibling directories sharing root_dir name p |
| CVE-2026-40110 | jupyter-server CORS origin validation bypass via unanchored regex in allow_origin_pat | |
| CVE-2026-40934 | jupyter-server authentication cookies remain valid after password reset due to static cook |
No comments yet