HIGH8.8CVE-2026-35397Jupyter Server: Path Traversal via incorrect startswith() root directory check allows access to sibling directories from 0
HIGH7.5CVE-2022-24757Insertion of Sensitive Information into Log File in Jupyter notebook from 0
HIGH7.3CVE-2026-40110Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat` (from huntr) from 0
HIGH7.1Jupyter server Token bruteforcing
from 0
MEDIUM6.8Jupyter Server's Authentication Cookies Remain Valid After Password Reset and Server Restart
from 0
MEDIUM6.1Jupyter Server has an open redirection vulnerability in `next` query parameter
from 0
MEDIUM6.1Open Redirect Vulnerability in jupyter-server
from 0
MEDIUM5.4Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP
from 0
MEDIUM4.6cross-site inclusion (XSSI) of files in jupyter-server
from 0
MEDIUM4.3jupyter-server errors include tracebacks with path information
from 0
MEDIUM4.1Open redirect in Jupyter Server
from 0, < 1.0.7-1