Skip to content
JupyterGHSA-7jqv-fw35-gmx9

nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding

Medium6.5CVE-2026-39378 · Published Apr 21, 2026 · updated Sep 10, 2026

## Summary When `HTMLExporter.embed_images=True`, nbconvert's markdown renderer allows arbitrary file read via path traversal in image references. A malicious notebook can exfiltrate sensitive files from the conversion host by embedding them as base64 data URIs in the output HTML. ## Patches Upgrade to nbconvert 7.17.1 ## Workarounds Do not enable `HTMLExporter.embed_images` (it is not enabled by default).

GitHub advisory

Affected versions

PackageAffectedFixed in
nbconvert
PyPI
>= 6.5.0, < 7.17.17.17.1
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-22, CWE-23
Also known as
CVE-2026-39378, PYSEC-2026-2230

More Jupyter advisories

All Jupyter

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.