Vulnerability PYSEC-2026-2683
Medium Risk
MEDIUM RISK
CVSS Score: 6.1
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 months ago
July 09, 2026 at 04:49 PM UTC
Open Redirect vulnerability in jupyterhub and notebook
0.0.0 - 5.7.6
0.0.0 - 5.7.6
Summary
Open Redirect vulnerability in jupyterhub and notebook
Details
An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.8 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.6 allows crafted links to the login page, which will redirect to a malicious site after successful login. Servers running on a base_url prefix are not affected.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
2 hours ago
JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard
7.5.0 - 7.6.2 PYSEC-2026-4112
7.5.0 - 7.6.2 PYSEC-2026-4112
High Risk
4 hours ago
JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard
7.5.0 - 7.6.2 GHSA-6966-vjj6-99xv
7.5.0 - 7.6.2 GHSA-6966-vjj6-99xv
Critical
2 months ago
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
7.0.0 - 7.5.5 PYSEC-2026-2681
7.0.0 - 7.5.5 PYSEC-2026-2681
Unknown
2 months ago
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
7.0.0 - 7.5.5 PYSEC-2026-2682
7.0.0 - 7.5.5 PYSEC-2026-2682
High Risk
2 months ago
HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering
7.0.0 - 7.2.1 PYSEC-2026-1481
7.0.0 - 7.2.1 PYSEC-2026-1481
Impacted packages
Timeline
Published
2 months ago
July 09, 2026 at 04:49 PM UTC
Fixed (5.7.8)
7 years ago
April 01, 2019 at 10:26 AM UTC
Last Modified
2 months ago
July 13, 2026 at 04:43 PM UTC