© 2025-2026 PySpect
First version without a known vulnerability: 5.4.5
JupyterHub has cross-origin form POSTs bypass XSRF (CWE-352)
Fixed in: 5.4.5
JupyterHub has an Open Redirect Vulnerability
Fixed in: 5.4.4
JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
Fixed in: 4.1.6, 5.1.0, 99e2720b0fc626cbeeca3c6337f917fdacfaa428, ff2db557a85b6980f90c3158634bf924063ab8ba
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
Fixed in: 4.1.0
Cross-Site Request Forgery in JupyterHub
Fixed in: 1.2.0b1
incomplete JupyterHub logout with simultaneous JupyterLab sessions
Fixed in: 1.5.0, 5ac9e7f73a6e1020ffddc40321fc53336829fe27
Open Redirect vulnerability in jupyterhub and notebook
Fixed in: 5.7.8, 0.9.6