Jupyter Vulnerabilities

pip AI Tools

AI Threat Alert tracks 42 known vulnerabilities in Jupyter, 6 rated critical — an AI/ML ai tools in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
28
Risk Score
42
Total CVEs
6
Critical
pip
Ecosystem
Sep 29, 2026
Last CVE
61%
Patch Rate
30d
Avg Time to Patch
13,391 stars 5,774 forks 1,888 issues 1,895 dependents Last push Sep 23, 2026
View on GitHub
OpenSSF Scorecard 5.8/10

Known Vulnerabilities (42 total, page 1 of 2)

Severity CVE ID Summary CVSS Published
MEDIUM CVE-2026-102904 JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.0.0 until 4.5.11 and 4.6.4, the PyPI Extension Manager uninstall request reaches ExtensionHandler.post, which validates extension names for installation but passes uninstall names to PyPIExtensionManager.uninstall and python -m pip uninstall without rejecting option-like values. The security impact requires that the PyPI Extension Manager is enabled, t 5.4 Sep 29, 2026 HIGH CVE-2026-102831 JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.5.0 until 4.5.11 and 4.6.4, from Notebook 7.5.0 until 7.6.3, and from JupyterLite Core 0.7.0 until 0.8.4, the system clipboard cell-paste path accepts attacker-controlled cell JSON without clearing metadata.trusted. When useSystemClipboardForCells is active and pasteCodeCellsWithoutOutput is disabled, a pasted code cell can mark HTML output as trusted, 8.1 Sep 29, 2026 MEDIUM CVE-2026-102830 JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 3.0.0 until 4.5.11 and 4.6.4, and in JupyterLite Core 0.8.3 and earlier, the Plural-Forms header in a selected third-party language pack can append JavaScript after a valid plural rule because prefix-only regular-expression validation accepts a matching prefix without requiring the entire header to match. JupyterLab passes the accepted expression to new 6.8 Sep 29, 2026 HIGH CVE-2026-86049 Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jupyter_server/log.py copies the Referer header into a JSON header block without applying the token scrubbing used for the request URI. A request that returns HTTP 500 while the Referer contains a token-bearing URL can therefore write that token to server logs in plaintext. An attacker who can read those logs can recover the token and use the affected user's Jupyter Server permiss 7.1 Sep 17, 2026 HIGH CVE-2026-59148 Mockoon: unauth admin API leaks secrets, hijacks mocks 8.8 Sep 11, 2026 MEDIUM CVE-2026-73627 JupyterLab: plugin lock bypass evades admin hardening -- Aug 13, 2026 HIGH CVE-2026-73626 JupyterLab: missing await bypasses extension allowlist 0.0 Aug 13, 2026 MEDIUM CVE-2026-54338 JupyterHub: unauth log flooding via long usernames 5.3 Aug 7, 2026 LOW GHSA-whvh-wf3x-g77j JupyterLab: missing await skips extension allowlist check -- Jul 22, 2026 MEDIUM GHSA-h5v5-8746-g7mm JupyterLab: plugin lock bypass via direct API access -- Jul 22, 2026 MEDIUM GHSA-89vp-jrxv-24w8 JupyterLab: extension blocklist bypass via name mismatch -- Jul 22, 2026 HIGH GHSA-gx64-gj6p-pc4c JupyterLab: image viewer XSS escalates to RCE -- Jul 22, 2026 HIGH GHSA-pppj-hq3g-57pj JupyterLab: crafted settings file executes code -- Jul 22, 2026 HIGH CVE-2026-23538 Feast: unauth WebSocket connections cause DoS 7.5 Jul 16, 2026 CRITICAL CVE-2026-23537 Feast: unauth file write to RCE via /save-document 9.1 Jul 1, 2026 HIGH CVE-2026-23536 Feast: unauth path traversal leaks any file 7.5 Mar 20, 2026 MEDIUM CVE-2026-52816 Gogs: XSS via data URI in ipynb sanitizer endpoint -- Jun 23, 2026 CRITICAL CVE-2026-54527 jupyterlab-git: stored XSS escalates to full RCE 9.0 Jun 19, 2026 HIGH CVE-2026-54528 jupyterlab-git: excluded_paths bypass exposes secrets 7.1 Jun 19, 2026 MEDIUM GHSA-vmhf-c436-hxj4 JupyterLab: XSS via malicious PyPI extension URL -- Jun 19, 2026 CRITICAL CVE-2026-44727 jupyter-server: stored XSS yields kernel RCE 9.0 Jun 18, 2026 CRITICAL CVE-2026-44180 Jupyter Enterprise Gateway: root privilege bypass in Kubernetes 9.8 Jun 3, 2026 UNKNOWN CVE-2026-44181 Enterprise Gateway: SSTI allows full K8s cluster compromise -- Jun 3, 2026 UNKNOWN CVE-2026-44182 Enterprise Gateway: YAML injection → K8s cluster takeover -- Jun 3, 2026 HIGH CVE-2026-6657 jupyter-server: CORS bypass enables arbitrary code execution 8.8 Jun 3, 2026

Showing 1–25 of 42

Frequently asked questions

What is Jupyter?

Jupyter is an AI/ML ai tools tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does Jupyter have?

Jupyter has 42 known CVEs, 6 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is Jupyter distributed in?

Jupyter is distributed via the pip ecosystem and categorized as ai tools.

Where does the Jupyter vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of Jupyter?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor Jupyter in your stack

Get instant alerts when new vulnerabilities affect Jupyter. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring