| Sep 17 | Jupyter Server: 5xx request logging leaks token-bearing Referer header values CVE-2026-86049High7.1fixed in 2.21.0 | High7.1 | 2.21.0 |
| Aug 25 | JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login CVE-2026-54338Medium5.3fixed in 5.5.0 | Medium5.3 | 5.5.0 |
| Jul 23 | jupyter-server is vulnerable to CORS origin validation bypass when the `allow_origin_pat` configuration is used CVE-2026-6657Medium6.1no fix yet | Medium6.1 | No fix yet |
| Jul 22 | JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`) CVE-2026-73417Highfixed in 4.5.10, 4.6.2 | High | 4.5.10, 4.6.2 |
| Jul 22 | JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab CVE-2026-73415Highfixed in 4.5.10, 4.6.2 | High | 4.5.10, 4.6.2 |
| Jul 22 | JupyterLab: PyPI extension blocklist package-name canonicalization bypass CVE-2026-73416Mediumfixed in 4.5.10, 4.6.2 | Medium | 4.5.10, 4.6.2 |
| Jul 22 | JupyterLab PluginManager lock-rule enforcement bypass GHSA-h5v5-8746-g7mmMediumfixed in 4.5.10, 4.6.2 | Medium | 4.5.10, 4.6.2 |
| Jul 22 | JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`) CVE-2026-73626Low0.0fixed in 4.5.10, 4.6.2 | Low0.0 | 4.5.10, 4.6.2 |
| Jul 13 | Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path() CVE-2026-5422Medium6.8fixed in 2.18.2 | Medium6.8 | 2.18.2 |
| Jun 19 | JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol CVE-2026-67338Mediumfixed in 4.5.9 | Medium | 4.5.9 |
| Jun 18 | Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP CVE-2026-44727Critical5.4fixed in 2.20.0 | Critical5.4 | 2.20.0 |
| May 6 | JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content CVE-2026-42557High9.6fixed in 4.5.7, 7.5.6 | High9.6 | 4.5.7, 7.5.6 |
| May 5 | JupyterLab has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST request CVE-2026-42266High8.8fixed in 4.5.7 | High8.8 | 4.5.7 |
| May 5 | JupyterHub has cross-origin form POSTs bypass XSRF (CWE-352) CVE-2026-40864Medium5.4fixed in 5.4.5 | Medium5.4 | 5.4.5 |
| May 5 | Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart CVE-2026-40934High6.8fixed in 2.18.0 | High6.8 | 2.18.0 |
| May 5 | Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat` CVE-2026-40110Highfixed in 2.18.0 | High | 2.18.0 |
| May 5 | Jupyter Server: Path Traversal via incorrect startswith() root directory check allows access to sibling directories CVE-2026-35397High7.1fixed in 2.18.0 | High7.1 | 2.18.0 |
| May 5 | Jupyter Server has an open redirection vulnerability in `next` query parameter CVE-2025-61669Mediumfixed in 2.18.0 | Medium | 2.18.0 |
| Apr 30 | Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS CVE-2026-40171Highfixed in 4.5.7, 7.5.6 | High | 4.5.7, 7.5.6 |
| Apr 21 | nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding CVE-2026-39378Medium6.5fixed in 7.17.1 | Medium6.5 | 7.17.1 |
| Apr 21 | nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames CVE-2026-39377Medium6.5fixed in 7.17.1 | Medium6.5 | 7.17.1 |
| Apr 3 | JupyterHub has an Open Redirect Vulnerability CVE-2026-33709Medium6.1fixed in 5.4.4 | Medium6.1 | 5.4.4 |
| Dec 182025 | nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windows CVE-2025-53000Highfixed in 7.17.0 | High | 7.17.0 |
| Sep 262025 | JupyterLab LaTeX typesetter links did not enforce `noopener` attribute CVE-2025-59842Lowfixed in 4.4.8 | Low | 4.4.8 |
| Aug 292024 | HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering CVE-2024-43805High7.6fixed in 3.6.8, 4.2.5, 7.2.2 | High7.6 | 3.6.8, 4.2.5, 7.2.2 |
| Aug 82024 | JupyterHub has a privilege escalation vulnerability with the `admin:users` scope CVE-2024-41942High7.2fixed in 4.1.6, 5.1.0 | High7.2 | 4.1.6, 5.1.0 |
| Jul 162024 | JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension authors hosting their code on GitHub are urged to upgrade the template CVE-2024-39700Critical9.8fixed in 4.3.0 | Critical9.8 | 4.3.0 |
| Jun 62024 | Jupyter server on Windows discloses Windows user password hash CVE-2024-35178High7.5fixed in 2.14.1 | High7.5 | 2.14.1 |
| Mar 282024 | Cross site scripting (XSS) in JupyterHub via Self-XSS leveraged by Cookie Tossing CVE-2024-28233High8.1fixed in 4.1.0 | High8.1 | 4.1.0 |
| Jan 192024 | JupyterLab vulnerable to potential authentication and CSRF tokens leak CVE-2024-22421High7.6fixed in 3.6.7, 4.0.11, 7.0.7 | High7.6 | 3.6.7, 4.0.11, 7.0.7 |
| Jan 192024 | JupyterLab vulnerable to SXSS in Markdown Preview CVE-2024-22420Medium6.5fixed in 4.0.11, 7.0.7 | Medium6.5 | 4.0.11, 7.0.7 |
| Dec 52023 | jupyter-server errors include tracebacks with path information CVE-2023-49080Medium4.3fixed in 2.11.2 | Medium4.3 | 2.11.2 |
| Aug 292023 | Open Redirect Vulnerability in jupyter-server CVE-2023-39968Medium6.1fixed in 2.7.2 | Medium6.1 | 2.7.2 |
| Aug 292023 | cross-site inclusion (XSSI) of files in jupyter-server CVE-2023-40170Medium4.6fixed in 2.7.2 | Medium4.6 | 2.7.2 |
| Aug 102022 | nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths CVE-2021-32862Medium5.4fixed in 6.5.1 | Medium5.4 | 6.5.1 |
| Jun 162022 | Jupyter server Token bruteforcing CVE-2022-29241High7.1fixed in 1.17.1, 2.0.0a1 | High7.1 | 1.17.1, 2.0.0a1 |
| Jun 162022 | Token bruteforcing. CVE-2022-29238Medium4.3fixed in 6.4.12 | Medium4.3 | 6.4.12 |
| May 242022 | Cross-Site Request Forgery in JupyterHub CVE-2020-36191Medium4.5fixed in 1.2.0b1 | Medium4.5 | 1.2.0b1 |
| May 172022 | Improper Input Validation in Jupyter Notebook CVE-2015-7337Critical9.8fixed in 4.0.5 | Critical9.8 | 4.0.5 |
| May 142022 | Improper Neutralization of Input During Web Page Generation in Jupyter Notebook CVE-2015-6938Medium6.1fixed in 4.0.5 | Medium6.1 | 4.0.5 |
| May 142022 | Improper Neutralization of Input During Web Page Generation in Jupyter Notebook CVE-2019-9644Medium5.4fixed in 5.7.6 | Medium5.4 | 5.7.6 |
| Apr 52022 | Sensitive Auth & Cookie data stored in Jupyter server logs CVE-2022-24758High7.5fixed in 6.4.10 | High7.5 | 6.4.10 |
| Mar 252022 | Insertion of Sensitive Information into Log File in Jupyter notebook CVE-2022-24757High7.5fixed in 1.15.4 | High7.5 | 1.15.4 |
| Nov 82021 | incomplete JupyterHub logout with simultaneous JupyterLab sessions CVE-2021-41247Medium3.5fixed in 1.5.0 | Medium3.5 | 1.5.0 |
| Aug 232021 | Special Element Injection in notebook CVE-2021-32798High10.0fixed in 5.7.11, 6.4.1 | High10.0 | 5.7.11, 6.4.1 |
| Aug 232021 | JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form> CVE-2021-32797Medium7.4fixed in 1.2.21, 2.2.10, 2.3.2, 3.0.17 | Medium7.4 | 1.2.21, 2.2.10, 2.3.2, 3.0.17 |
| Dec 212020 | Jupyter Server open redirect vulnerability CVE-2020-26275Medium6.1fixed in 1.1.1 | Medium6.1 | 1.1.1 |
| Nov 242020 | Open redirect in Jupyter Server CVE-2020-26232Medium4.1fixed in 1.0.6 | Medium4.1 | 1.0.6 |
| Nov 182020 | Open redirect in Jupyter Notebook CVE-2020-26215Low4.4fixed in 6.1.5 | Low4.4 | 6.1.5 |
| Nov 82019 | Cross-site scripting in Jupyter Notebook CVE-2018-21030Medium5.3fixed in 5.5.0rc1 | Medium5.3 | 5.5.0rc1 |
| Apr 92019 | Jupyter Notebook open redirect vulnerability CVE-2019-10856Medium6.1fixed in 5.7.8 | Medium6.1 | 5.7.8 |
| Apr 22019 | Open Redirect vulnerability in jupyterhub and notebook CVE-2019-10255Medium6.1fixed in 0.9.6, 5.7.8 | Medium6.1 | 0.9.6, 5.7.8 |
| Nov 212018 | Jupyter Notebook XSS via directory name CVE-2018-19352Medium6.1fixed in 5.7.2 | Medium6.1 | 5.7.2 |
| Nov 212018 | Jupyter Notebook XSS via untrusted notebooks CVE-2018-19351Medium6.1fixed in 5.7.1 | Medium6.1 | 5.7.1 |
| Jul 122018 | Jupyter Notebook file bypasses sanitization, executes JavaScript CVE-2018-8768High7.8fixed in 5.4.1 | High7.8 | 5.4.1 |