Jupyter Enterprise Gateway是Jupyter组织的一款网络设备产品。 Jupyter Enterprise Gateway 2.0.0rc2至3.3.0之前版本存在代码注入漏洞,该漏洞源于在渲染Kubernetes manifest时使用的环境变量(KERNEL_XXX)容易受到服务器端模板注入(SSTI)攻击,可能导致执行Python代码和OS命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jupyter-server | enterprise_gateway | >= 2.0.0rc2, < 3.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jupyter-server | enterprise_gateway | >= 2.0.0rc2, < 3.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-44180 | 9.8 CRITICAL | Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids can be Bypassed |
| CVE-2026-44182 | Jupyter Enterprise Gateway Has Kubernetes Manifest Injection via Jinja2 Template Rendering |
No comments yet