Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Jupyter

First CVE: Sep 21, 2015Active for: 11 yearsTotal CVEs: 64
29.1
VTI Score
Low

Jupyter's vulnerability footprint concentrates in a focused but broadly deployed ecosystem of web-based data-science and notebook-collaboration platforms, spanning Notebook, JupyterLab, JupyterHub, and related authentication components that sit at the boundary between user code execution and web access. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, reflecting the exposure inherent to interactive execution environments that often run with elevated privileges and handle user-supplied code and content. The exposure recurs through web-layer weakness classes including cross-site scripting, open redirect, path traversal, and CSRF, patterns typical of Python-based web applications where input sanitization and session management are critical to isolating execution contexts and protecting notebook state. Defenders should treat Jupyter deployments as high-value targets—particularly internet-facing instances and those integrated with shared infrastructure—and prioritize patching, since the platform's role in data science and machine-learning pipelines means compromise can affect downstream analytics and model integrity. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
64
Total CVEs
More Total CVEs than 99% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Jupyter over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 21, 2015
10 years ago
Most Recent CVE
Jul 8, 2026
16 days ago

Products(15 total)

Top CVEs

Signals from CVEs in this vendor scope (64 CVEs).

64 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-54527CRITICAL
JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames directly to innerHTML when rendering
Jul 8, 20269.040NONO
CVE-2026-42557CRITICAL
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.7, JupyterLab's HTML sanitizer allowlis
May 13, 20269.637NONO
CVE-2026-42266HIGH
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions th
May 13, 20268.837NONO
CVE-2026-35397HIGH
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape th
May 5, 20268.836NONO
CVE-2026-5422HIGH
A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check in the _get_os_path() function within jupyter_server/servic
Jun 2, 20268.134NONO
CVE-2026-6657HIGH
A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` configuration is used. The issue ar
Jun 3, 20268.833NONO
CVE-2026-40110HIGH
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming origins against
May 5, 20267.332NONO
CVE-2024-39700CRITICAL
JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml`
Jul 16, 20249.831NONO
CVE-2021-32798CRITICAL
The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load. Jupyter Notebook uses a deprec
Aug 9, 20219.631NONO
CVE-2021-32797CRITICAL
JupyterLab is a user interface for Project Jupyter which will eventually replace the classic Jupyter Notebook. In affected versions untrusted notebook can execute code on load. In
Aug 9, 20219.631NONO
View all 64 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products64 CVEs
55%
30%
16%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (4.7%)
Network59 (92.2%)
Unknown2 (3.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low59 (92.2%)
High3 (4.7%)
Unknown2 (3.1%)
User Interaction
None28 (43.8%)
Unknown2 (3.1%)
Required34 (53.1%)
Privileges Required
Low22 (34.4%)
High2 (3.1%)
None38 (59.4%)
Unknown2 (3.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (64 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Jupyter.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Jupyter — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Jupyter's Products

View all 3 CNAs →

Top CWEs