Jupyter Server是Jupyter组织的一款用于为Jupyter Web应用提供后端服务的应用软件。 Jupyter Server 2.17.0及之前版本存在代码问题漏洞,该漏洞源于用于签名认证cookie的密钥持久化到静态文件且用户更改密码后不轮换,可能导致攻击者通过捕获的会话cookie在密码更改后仍保持完全认证访问。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jupyter-server | jupyter_server | < 2.18.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jupyter-server | jupyter_server | < 2.18.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-35397 | 7.6 HIGH | jupyter-server path traversal allows access to sibling directories sharing root_dir name p |
| CVE-2025-61669 | jupyter_server next parameter open redirect can redirect users to external domains | |
| CVE-2026-40110 | jupyter-server CORS origin validation bypass via unanchored regex in allow_origin_pat |
No comments yet