An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allows crafted links to the login page, which will redirect to a malicious site after successful login. Servers running on a base_url prefix are not affected.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade jupyter-notebook | Jul 30, 2024 | Mar 28, 2019 |
| Freebsd | — | Upgrade py36-notebookUpgrade py37-notebookUpgrade py35-notebookUpgrade py27-notebook | Dec 10, 2025 | Mar 29, 2019 |
| Ubuntu | — | Upgrade jupyter-notebookUpgrade python3-notebookUpgrade python-notebook | Aug 31, 2022 | Mar 28, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub