Jupyter Notebook Vulnerabilities

pip AI Tools

AI Threat Alert tracks 59 known vulnerabilities in Jupyter Notebook, 10 rated critical — an AI/ML ai tools in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
32
Risk Score
59
Total CVEs
10
Critical
pip
Ecosystem
Oct 1, 2026
Last CVE
85%
Patch Rate
92d
Avg Time to Patch
13,391 stars 5,774 forks 1,888 issues 3,049 dependents Last push Sep 23, 2026
View on GitHub
OpenSSF Scorecard 5.8/10

Known Vulnerabilities (58 total, page 1 of 3)

Severity CVE ID Summary CVSS Published
MEDIUM CVE-2026-73609 SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering 5.8 Oct 1, 2026 HIGH GHSA-9cqf-hhrq-7v45 SiYuan: getAttributeViewSearchTarget returns database row content to anonymous readers with no publish-access check, reopening the class closed one day earlier at the adjacent route 8.6 Oct 1, 2026 MEDIUM CVE-2026-73606 SiYuan: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block 5.8 Oct 1, 2026 CRITICAL CVE-2026-92939 vm2 crypto builtin loads attacker native code through setEngine 9.9 Oct 1, 2026 CRITICAL CVE-2026-92938 vm2 allows a sandboxed plugin to execute native code through `node:sqlite` 9.9 Oct 1, 2026 HIGH CVE-2026-102831 JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From JupyterLab 4.5.0 until 4.5.11 and 4.6.4, from Notebook 7.5.0 until 7.6.3, and from JupyterLite Core 0.7.0 until 0.8.4, the system clipboard cell-paste path accepts attacker-controlled cell JSON without clearing metadata.trusted. When useSystemClipboardForCells is active and pasteCodeCellsWithoutOutput is disabled, a pasted code cell can mark HTML output as trusted, 8.1 Sep 29, 2026 HIGH CVE-2026-61647 NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content to local vault directories. Versions 1.6.0 through 2.0.2 contain a path traversal vulnerability in the `POST /batch-to-vault` endpoint, also exposed through the `batch_to_vault` MCP tool beginning in version 1.7.0, because attacker-controlled `vault_dir` and `slug_prefix` values can cause Markdown and JSON files to be written outside the intended vault directory to any location -- Sep 21, 2026 HIGH CVE-2026-80206 NLTK tgrep ReDoS: single request hangs Python process -- Sep 8, 2026 MEDIUM GHSA-57v5-wqx3-cgj4 SiYuan: missing authz leaks database view structure 5.8 Sep 8, 2026 MEDIUM CVE-2026-65915 NLTK: dead sandbox check enables arbitrary file read 6.5 Sep 8, 2026 HIGH CVE-2026-72794 SiYuan: CookieKey leak enables session forgery 8.6 Sep 4, 2026 HIGH CVE-2026-69086 SiYuan: path traversal leaks attribute-view data 7.7 Sep 3, 2026 HIGH CVE-2026-68587 SiYuan: missing authz exposes publish-disabled docs 8.6 Sep 3, 2026 HIGH CVE-2026-68586 SiYuan: missing authz leaks forbidden doc content via backlink API 8.6 Sep 3, 2026 HIGH GHSA-7j72-f6wg-cxw6 SiYuan: auth bypass leaks password-protected doc content 8.6 Sep 3, 2026 MEDIUM CVE-2026-72812 SiYuan: broken auth on refreshBacklink enables DoS 6.5 Sep 3, 2026 HIGH CVE-2026-72810 SiYuan: WebSocket leak bypasses publish access control 8.6 Sep 3, 2026 MEDIUM CVE-2026-72805 SiYuan: auth bypass exposes private notebook content 5.8 Sep 3, 2026 MEDIUM CVE-2026-72800 SiYuan: broken authz leaks DB schema & block IDs 5.8 Sep 3, 2026 HIGH CVE-2026-59834 Siyuan: SQLi bypasses publish visibility control 7.5 Sep 2, 2026 CRITICAL CVE-2026-72811 SiYuan: SQL injection enables cross-notebook DB access 10.0 Aug 14, 2026 HIGH CVE-2026-72793 SiYuan: getConf leaks session key, enables admin takeover 8.6 Aug 12, 2026 MEDIUM CVE-2026-72808 SiYuan: authZ gap leaks private PDF annotations 5.8 Aug 12, 2026 HIGH CVE-2026-72807 SiYuan: second-order SQLi via malicious template packages 8.0 Aug 12, 2026 HIGH CVE-2026-72801 SiYuan: key material leak enables offline cracking 7.5 Aug 12, 2026

Showing 1–25 of 58

Frequently asked questions

What is Jupyter Notebook?

Jupyter Notebook is an AI/ML ai tools tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does Jupyter Notebook have?

Jupyter Notebook has 59 known CVEs, 10 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is Jupyter Notebook distributed in?

Jupyter Notebook is distributed via the pip ecosystem and categorized as ai tools.

Where does the Jupyter Notebook vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of Jupyter Notebook?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor Jupyter Notebook in your stack

Get instant alerts when new vulnerabilities affect Jupyter Notebook. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring