OVERVIEW: CVE-2026-39378 is a path traversal vulnerability in Jupyter nbconvert versions 6.5 through 7.17.0 that allows arbitrary file read when the HTMLExporter.embed_images feature is enabled. A malicious notebook can exploit this vulnerability to exfiltrate sensitive files from the conversion host by embedding them as base64-encoded data URIs in the output HTML. The vulnerability has been patched in nbconvert 7.17.1, and users can mitigate risk by disabling the embed_images option, which is not enabled by default. SEVERITY: The vulnerability carries a CVSS score of 6.5 (Medium) with a network attack vector, low attack complexity, and no required user privileges. The primary impact is confidentiality loss through unauthorized file access, though integrity and availability are not affected. Exploitation requires user interaction to process a malicious notebook, limiting the attack surface to scenarios where untrusted notebooks are converted. EXPLOITATION STATUS: The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog and shows no active exploitation in the wild. The EPSS score of 0.00036 indicates minimal probability of exploitation compared to industry baselines. Community attention remains low, reflected in the moderate FAUCET risk score of 44.0/100, suggesting this is a lower-priority threat requiring standard patching procedures rather than emergency response.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.5.0, < 7.17.1CPE matchmatch criteria | cpe:2.3:a:jupyter:nbconvert:*:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.