Jupyter Vulnerabilities

pip AI Tools

AI Threat Alert tracks 36 known vulnerabilities in Jupyter, 5 rated critical — an AI/ML ai tools in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
28
Risk Score
36
Total CVEs
5
Critical
pip
Ecosystem
Aug 13, 2026
Last CVE
54%
Patch Rate
28d
Avg Time to Patch
13,300 stars 5,737 forks 1,908 issues 1,886 dependents Last push Aug 11, 2026
View on GitHub
OpenSSF Scorecard 5.7/10

Known Vulnerabilities (36 total, page 1 of 2)

Severity CVE ID Summary CVSS Published
MEDIUM CVE-2026-73627 JupyterLab: plugin lock bypass evades admin hardening -- Aug 13, 2026 UNKNOWN CVE-2026-73626 JupyterLab: missing await bypasses extension allowlist 0.0 Aug 13, 2026 LOW GHSA-whvh-wf3x-g77j JupyterLab: missing await skips extension allowlist check -- Jul 22, 2026 MEDIUM GHSA-h5v5-8746-g7mm JupyterLab: plugin lock bypass via direct API access -- Jul 22, 2026 MEDIUM GHSA-89vp-jrxv-24w8 JupyterLab: extension blocklist bypass via name mismatch -- Jul 22, 2026 HIGH GHSA-gx64-gj6p-pc4c JupyterLab: image viewer XSS escalates to RCE -- Jul 22, 2026 HIGH GHSA-pppj-hq3g-57pj JupyterLab: crafted settings file executes code -- Jul 22, 2026 HIGH CVE-2026-23538 Feast: unauth WebSocket connections cause DoS 7.5 Jul 16, 2026 CRITICAL CVE-2026-23537 Feast: unauth file write to RCE via /save-document 9.1 Jul 1, 2026 HIGH CVE-2026-23536 Feast: unauth path traversal leaks any file 7.5 Mar 20, 2026 MEDIUM CVE-2026-52816 Gogs: XSS via data URI in ipynb sanitizer endpoint -- Jun 23, 2026 UNKNOWN CVE-2026-54527 jupyterlab-git: stored XSS escalates to full RCE -- Jun 19, 2026 HIGH CVE-2026-54528 jupyterlab-git: excluded_paths bypass exposes secrets 7.1 Jun 19, 2026 MEDIUM GHSA-vmhf-c436-hxj4 JupyterLab: XSS via malicious PyPI extension URL -- Jun 19, 2026 CRITICAL CVE-2026-44727 jupyter-server: stored XSS yields kernel RCE 9.0 Jun 18, 2026 CRITICAL CVE-2026-44180 Jupyter Enterprise Gateway: root privilege bypass in Kubernetes 9.8 Jun 3, 2026 UNKNOWN CVE-2026-44181 Enterprise Gateway: SSTI allows full K8s cluster compromise -- Jun 3, 2026 UNKNOWN CVE-2026-44182 Enterprise Gateway: YAML injection → K8s cluster takeover -- Jun 3, 2026 HIGH CVE-2026-6657 jupyter-server: CORS bypass enables arbitrary code execution 8.8 Jun 3, 2026 HIGH CVE-2026-5422 jupyter-server: path traversal exposes sibling dir files 8.1 Jun 2, 2026 HIGH CVE-2026-42557 JupyterLab: one-click RCE via notebook HTML cell output 8.8 May 6, 2026 HIGH CVE-2026-33079 mistune: ReDoS exposes Jupyter/AI services to DoS 7.5 May 6, 2026 HIGH CVE-2026-42266 JupyterLab: Extension allow-list bypass enables privesc 8.8 May 5, 2026 MEDIUM CVE-2025-61669 jupyter-server: Open redirect enables credential phishing -- May 5, 2026 HIGH CVE-2026-35397 Jupyter Server: path traversal leaks sibling directories 7.1 May 5, 2026

Showing 1–25 of 36

Frequently asked questions

What is Jupyter?

Jupyter is an AI/ML ai tools tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does Jupyter have?

Jupyter has 36 known CVEs, 5 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is Jupyter distributed in?

Jupyter is distributed via the pip ecosystem and categorized as ai tools.

Where does the Jupyter vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of Jupyter?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor Jupyter in your stack

Get instant alerts when new vulnerabilities affect Jupyter. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring