Skip to content
JupyterGHSA-7r3h-4ph8-w38g

Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing

High8.1CVE-2024-28233 · Published Mar 28, 2024 · updated Sep 10, 2026

### Impact Affected configurations: - Single-origin JupyterHub deployments - JupyterHub deployments with user-controlled applications running on subdomains or peer subdomains of either the Hub or a single-user server. By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve the following: - Full access to JupyterHub API and user's single-user server, e.g. - Create and exfiltrate an API Token - Exfiltrate all files hosted on the user's single-user server: notebooks, images, etc. - Install malicious extensions. They can be used as a backdoor to silently regain access to victim's session anytime. ### Patches To prevent cookie-tossing: - Upgrade to JupyterHub 4.1 (both hub and user environment) - enable per-user domains via `c.JupyterHub.subdomain_host = "https://mydomain.example.org"` - set `c.JupyterHub.cookie_host_prefix_enabled = True` to enable domain-locked cookies or, if available (applies to earlier JupyterHub versions): - deploy jupyterhub on its own domain, not shared with any other services - enable per-user domains via `...

GitHub advisory

Affected versions

PackageAffectedFixed in
jupyterhub
PyPI
< 4.1.04.1.0
Details and references

### Impact Affected configurations: - Single-origin JupyterHub deployments - JupyterHub deployments with user-controlled applications running on subdomains or peer subdomains of either the Hub or a single-user server. By tricking a user into visiting a malicious subdomain, the attacker can achieve an XSS directly affecting the former's session. More precisely, in the context of JupyterHub, this XSS could achieve the following: - Full access to JupyterHub API and user's single-user server, e.g. - Create and exfiltrate an API Token - Exfiltrate all files hosted on the user's single-user server: notebooks, images, etc. - Install malicious extensions. They can be used as a backdoor to silently regain access to victim's session anytime. ### Patches To prevent cookie-tossing: - Upgrade to JupyterHub 4.1 (both hub and user environment) - enable per-user domains via `c.JupyterHub.subdomain_host = "https://mydomain.example.org"` - set `c.JupyterHub.cookie_host_prefix_enabled = True` to enable domain-locked cookies or, if available (applies to earlier JupyterHub versions): - deploy jupyterhub on its own domain, not shared with any other services - enable per-user domains via `c.JupyterHub.subdomain_host = "https://mydomain.example.org"`

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-352, CWE-565, CWE-79
Also known as
BIT-jupyterhub-2024-28233, CVE-2024-28233, PYSEC-2026-1480

More Jupyter advisories

All Jupyter
Advisory
JupyterHub has a privilege escalation vulnerability with the `admin:users` scope
High7.2Aug 8, 2024
JupyterLab extension template is a `copier` template for JupyterLab extensions
Critical9.8Jul 16, 2024
Jupyter server on Windows discloses Windows user password hash
High7.5Jun 6, 2024
JupyterLab vulnerable to potential authentication and CSRF tokens leak
High7.6Jan 19, 2024
JupyterLab vulnerable to SXSS in Markdown Preview
Medium6.5Jan 19, 2024
jupyter-server errors include tracebacks with path information
Medium4.3Dec 5, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.