Skip to content
JupyterGHSA-64x5-55rw-9974

cross-site inclusion (XSSI) of files in jupyter-server

Medium4.6CVE-2023-40170 · Published Aug 29, 2023 · updated Sep 10, 2026

### Impact Improper cross-site credential checks on `/files/` URLs could allow exposure of certain file contents, or accessing files when opening untrusted files via "Open image in new tab". ### Patches Jupyter Server 2.7.2 ### Workarounds Use lower performance `--ContentsManager.files_handler_class=jupyter_server.files.handlers.FilesHandler`, which implements the correct checks. ### References Upstream patch for CVE-2019-9644 was not applied completely, leaving part of the vulnerability open. Vulnerability reported by Tim Coen via the [bug bounty program](https://app.intigriti.com/programs/jupyter/jupyter/detail) [sponsored by the European Commission](https://commission.europa.eu/news/european-commissions-open-source-programme-office-starts-bug-bounties-2022-01-19_en) and hosted on the [Intigriti platform](https://www.intigriti.com/).

GitHub advisory

Affected versions

PackageAffectedFixed in
jupyter-server
PyPI
< 2.7.22.7.2
Details and references

More Jupyter advisories

All Jupyter
Advisory
Jupyter server on Windows discloses Windows user password hash
High7.5Jun 6, 2024
Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing
High8.1Mar 28, 2024
JupyterLab vulnerable to potential authentication and CSRF tokens leak
High7.6Jan 19, 2024
JupyterLab vulnerable to SXSS in Markdown Preview
Medium6.5Jan 19, 2024
jupyter-server errors include tracebacks with path information
Medium4.3Dec 5, 2023
Open Redirect Vulnerability in jupyter-server
Medium6.1Aug 29, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.