© 2025-2026 PySpect
First version without a known vulnerability: 2.20.0
jupyter-server is vulnerable to CORS origin validation bypass when the `allow_origin_pat` configuration is used
Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path()
Fixed in: 2.18.2
Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP
Fixed in: 2.20.0
Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart
Fixed in: 2.18.0
Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat`
Fixed in: 2.18.0
Jupyter Server: Path Traversal via incorrect startswith() root directory check allows access to sibling directories
Fixed in: 2.18.0
Jupyter Server has an open redirection vulnerability in `next` query parameter
Fixed in: 2.18.0
Jupyter server on Windows discloses Windows user password hash
Fixed in: 2.14.1, 79fbf801c5908f4d1d9bc90004b74cfaaeeed2df
jupyter-server errors include tracebacks with path information
Fixed in: 2.11.2, 0056c3aa52cbb28b263a7a609ae5f17618b36652
Open Redirect Vulnerability in jupyter-server
Fixed in: 2.7.2, 290362593b2ffb23c59f8114d76f77875de4b925
cross-site inclusion (XSSI) of files in jupyter-server
Fixed in: 2.7.2, 87a4927272819f0b1cae1afa4c8c86ee2da002fd
Jupyter server Token bruteforcing
Fixed in: 1.17.1, 2.0.0a1, 1.17.0
Insertion of Sensitive Information into Log File in Jupyter notebook
Fixed in: 1.15.4, a5683aca0b0e412672ac6218d09f74d44ca0de5a
Jupyter Server open redirect vulnerability
Fixed in: 1.1.1, 85e4abccf6ea9321d29153f73b0bd72ccb3a6bca
Open redirect in Jupyter Server
Fixed in: 1.0.6, 3d83e49090289c431da253e2bdb8dc479cbcb157