Skip to content
JupyterGHSA-rv62-4pmj-xw6h

Open Redirect vulnerability in jupyterhub and notebook

Medium6.1CVE-2019-10255 · Published Apr 2, 2019 · updated Jul 13, 2026

An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.8 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.6 allows crafted links to the login page, which will redirect to a malicious site after successful login. Servers running on a base_url prefix are not affected.

GitHub advisory

Affected versions

PackageAffectedFixed in
jupyterhub
PyPI
< 0.9.60.9.6
notebook
PyPI
< 5.7.85.7.8
Details and references

More Jupyter advisories

All Jupyter
Advisory
Open redirect in Jupyter Notebook
Low4.4Nov 18, 2020
Cross-site scripting in Jupyter Notebook
Medium5.3Nov 8, 2019
Jupyter Notebook open redirect vulnerability
Medium6.1Apr 9, 2019
Jupyter Notebook XSS via directory name
Medium6.1Nov 21, 2018
Jupyter Notebook XSS via untrusted notebooks
Medium6.1Nov 21, 2018
Jupyter Notebook file bypasses sanitization, executes JavaScript
High7.8Jul 12, 2018

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.