Jupyter Server是Jupyter组织的一款用于为Jupyter Web应用提供后端服务的应用软件。 Jupyter Server 2.17.0及之前版本存在路径遍历漏洞,该漏洞源于REST API中的路径遍历问题,可能导致经过身份验证的用户逃离配置的root_dir并访问名称以root_dir前缀开头的同级目录。以下版本受到影响:2.17.0及之前版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jupyter-server | jupyter_server | < 2.18.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jupyter-server | jupyter_server | < 2.18.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-61669 | jupyter_server next parameter open redirect can redirect users to external domains | |
| CVE-2026-40110 | jupyter-server CORS origin validation bypass via unanchored regex in allow_origin_pat | |
| CVE-2026-40934 | jupyter-server authentication cookies remain valid after password reset due to static cook |
No comments yet