Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39378

23
FAUCET Score

OVERVIEW: CVE-2026-39378 is a path traversal vulnerability in Jupyter nbconvert versions 6.5 through 7.17.0 that allows arbitrary file read when the HTMLExporter.embed_images feature is enabled. A malicious notebook can exploit this vulnerability to exfiltrate sensitive files from the conversion host by embedding them as base64-encoded data URIs in the output HTML. The vulnerability has been patched in nbconvert 7.17.1, and users can mitigate risk by disabling the embed_images option, which is not enabled by default. SEVERITY: The vulnerability carries a CVSS score of 6.5 (Medium) with a network attack vector, low attack complexity, and no required user privileges. The primary impact is confidentiality loss through unauthorized file access, though integrity and availability are not affected. Exploitation requires user interaction to process a malicious notebook, limiting the attack surface to scenarios where untrusted notebooks are converted. EXPLOITATION STATUS: The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog and shows no active exploitation in the wild. The EPSS score of 0.00036 indicates minimal probability of exploitation compared to industry baselines. Community attention remains low, reflected in the moderate FAUCET risk score of 44.0/100, suggesting this is a lower-priority threat requiring standard patching procedures rather than emergency response.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.5.0, < 7.17.1CPE matchmatch criteria
cpe:2.3:a:jupyter:nbconvert:*:*:*:*:*:python:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.31%
Probability of exploitation in next 30 days
EPSS Percentile
22.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0031 is in the 23rd percentile among its peer group of 26,236 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

pippatch availablevia ghsa
Product: nbconvertFixed in: 7.17.1

Vendor Advisories (1)

pipGHSA-7jqv-fw35-gmx9medium

nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding

Apr 21, 2026

References

github.com / jupyter/nbconvert/releases/tag/v7.17.1
Product
github.com / jupyter/nbconvert/security/advisories/GHSA-7jqv-fw35-gmx9
MitigationVendor Advisory