Jupyter Notebook Vulnerabilities

pip AI Tools

AI Threat Alert tracks 59 known vulnerabilities in Jupyter Notebook, 10 rated critical — an AI/ML ai tools in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
32
Risk Score
59
Total CVEs
10
Critical
pip
Ecosystem
Oct 1, 2026
Last CVE
85%
Patch Rate
92d
Avg Time to Patch
13,391 stars 5,774 forks 1,888 issues 3,049 dependents Last push Sep 23, 2026
View on GitHub
OpenSSF Scorecard 5.8/10

Known Vulnerabilities (58 total, page 2 of 3)

Severity CVE ID Summary CVSS Published
MEDIUM CVE-2026-72799 SiYuan: broken access control exposes private docs 5.8 Aug 12, 2026 MEDIUM CVE-2026-72797 SiYuan: missing authz leaks encrypted notebook metadata 5.8 Aug 12, 2026 MEDIUM CVE-2026-72790 SiYuan: missing authz leaks notebook metadata 5.8 Aug 12, 2026 HIGH CVE-2026-72789 SiYuan: broken access control leaks encrypted notes 8.6 Aug 12, 2026 MEDIUM CVE-2026-72788 SiYuan: unauth info leak exposes admin workspace via getConf 5.8 Aug 12, 2026 CRITICAL CVE-2026-69083 SiYuan: unauthenticated SQLi in full-text search endpoint 10.0 Aug 3, 2026 CRITICAL CVE-2026-69085 SiYuan: SQL injection in searchDocs allows DB tampering 10.0 Aug 3, 2026 CRITICAL CVE-2026-69084 SiYuan: SQL injection in search endpoint exposes notebooks 10.0 Aug 3, 2026 MEDIUM CVE-2026-68585 SiYuan: metadata leak bypasses publish-access checks 5.8 Aug 3, 2026 HIGH GHSA-p7w7-4929-vpj5 Dynatrace MCP server: unauth HTTP data exfil via DQL 7.5 Jul 31, 2026 LOW GHSA-pc2w-4mq8-32qw Dynatrace MCP: notebook tool skips approval gate 3.7 Jul 29, 2026 LOW GHSA-whvh-wf3x-g77j JupyterLab: missing await skips extension allowlist check -- Jul 22, 2026 MEDIUM GHSA-h5v5-8746-g7mm JupyterLab: plugin lock bypass via direct API access -- Jul 22, 2026 MEDIUM CVE-2026-53656 FiftyOne: wildcard CORS enables local file exfiltration 6.3 Jul 15, 2026 HIGH CVE-2026-54066 SiYuan: /assets path traversal exposes API secrets 7.5 Jul 10, 2026 CRITICAL CVE-2026-54069 SiYuan Note: chrome-extension origin auth bypass -- Jul 10, 2026 HIGH CVE-2026-52798 Gogs: Stored XSS via .ipynb Markdown re-render bypass 8.9 Jun 22, 2026 HIGH GHSA-6vxv-wg6j-5qwp Gogs: XSS via outdated Jupyter renderer, account takeover -- Jun 19, 2026 CRITICAL CVE-2026-44727 jupyter-server: stored XSS yields kernel RCE 9.0 Jun 18, 2026 MEDIUM CVE-2026-54386 marimo: reflected XSS enables JS injection in notebooks 6.1 Jun 17, 2026 HIGH CVE-2026-54293 NLTK: path traversal leaks arbitrary local files 7.5 Jun 16, 2026 MEDIUM CVE-2024-11831 serialize-javascript: XSS via regex in AI/ML dashboards 5.4 Feb 10, 2025 HIGH CVE-2026-5422 jupyter-server: path traversal exposes sibling dir files 8.1 Jun 2, 2026 HIGH CVE-2026-42557 JupyterLab: one-click RCE via notebook HTML cell output 8.8 May 6, 2026 HIGH CVE-2026-42266 JupyterLab: Extension allow-list bypass enables privesc 8.8 May 5, 2026

Showing 26–50 of 58

Frequently asked questions

What is Jupyter Notebook?

Jupyter Notebook is an AI/ML ai tools tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does Jupyter Notebook have?

Jupyter Notebook has 59 known CVEs, 10 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is Jupyter Notebook distributed in?

Jupyter Notebook is distributed via the pip ecosystem and categorized as ai tools.

Where does the Jupyter Notebook vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of Jupyter Notebook?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor Jupyter Notebook in your stack

Get instant alerts when new vulnerabilities affect Jupyter Notebook. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring