Skip to content
JupyterGHSA-rcx2-m7jp-p9wj

Jupyter Notebook open redirect vulnerability

Medium6.1CVE-2019-10856 · Published Apr 9, 2019 · updated Sep 26, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
notebook
PyPI
< 5.7.85.7.8
Details and references

In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists because of an incomplete fix for CVE-2019-10255.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-601
Also known as
CVE-2019-10856, PYSEC-2019-158

More Jupyter advisories

All Jupyter
DateAdvisory
Apr 22019Open Redirect vulnerability in jupyterhub and notebook
CVE-2019-10255Medium6.1fixed in 0.9.6, 5.7.8
Nov 212018Jupyter Notebook XSS via directory name
CVE-2018-19352Medium6.1fixed in 5.7.2
Nov 212018Jupyter Notebook XSS via untrusted notebooks
CVE-2018-19351Medium6.1fixed in 5.7.1
Nov 82019Cross-site scripting in Jupyter Notebook
CVE-2018-21030Medium5.3fixed in 5.5.0rc1
Jul 122018Jupyter Notebook file bypasses sanitization, executes JavaScript
CVE-2018-8768High7.8fixed in 5.4.1
Nov 182020Open redirect in Jupyter Notebook
CVE-2020-26215Low4.4fixed in 6.1.5

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.