Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39377

24
FAUCET Score

OVERVIEW CVE-2026-39377 is a path traversal vulnerability in Jupyter nbconvert versions 6.5 through 7.17.0 that allows arbitrary file writes outside the intended output directory. The vulnerability exists in the ExtractAttachmentsPreprocessor component, which fails to sanitize attachment filenames from Jupyter notebooks before writing them to the filesystem. An attacker can craft malicious notebooks with specially formatted cell attachment filenames to write files to arbitrary locations with controlled extensions. SEVERITY The vulnerability carries a CVSS v3.1 score of 6.5 (MEDIUM) with a network-based attack vector requiring no special privileges but dependent on user interaction. Attack complexity is low, meaning an attacker simply needs to deliver a malicious notebook for processing. The primary impact is integrity compromise, as attackers gain complete control over file destination paths and extensions, potentially enabling code execution through strategic file placement. Confidentiality and availability are not directly affected. EXPLOITATION STATUS There are no confirmed reports of active exploitation, and this vulnerability does not appear on CISA's Known Exploited Vulnerabilities (KEV) catalog. The EPSS score of 0.0004 indicates minimal real-world exploitation likelihood relative to other vulnerabilities. No public exploit code has achieved notable community attention, suggesting limited awareness or weaponization. Users should prioritize patching to version 7.17.1 or later as a precautionary measure, particularly if processing notebooks from untrusted sources.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.5.0, < 7.17.1CPE matchmatch criteria
cpe:2.3:a:jupyter:nbconvert:*:*:*:*:*:python:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.27%
Probability of exploitation in next 30 days
EPSS Percentile
18.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0027 is in the 19th percentile among its peer group of 26,236 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

pippatch availablevia ghsa
Product: nbconvertFixed in: 7.17.1

Vendor Advisories (1)

pipGHSA-4c99-qj7h-p3vgmedium

nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames

Apr 21, 2026

References

github.com / jupyter/nbconvert/releases/tag/v7.17.1
Product
github.com / jupyter/nbconvert/security/advisories/GHSA-4c99-qj7h-p3vg
MitigationVendor Advisory